Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Difficulties With Vundofix.exe


  • Please log in to reply
9 replies to this topic

#1 Clayboy

Clayboy

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:02 PM

Posted 27 January 2006 - 03:10 PM

This post is in reference to:
http://www.bleepingcomputer.com/forums/t/18610/how-to-remove-winfixer-virtumonde-msevents-trojanvundob/

The link in the "Tools Needed" section is actually a DOS type version not matching the post description. I ran it and not my Windows GUI is all a rye. Basically, the desktop is blank. The task bar and start menus are absent. I am able to run applications through Task Manager but everything is manual.

Below is my HiJackThis log. Anyone care to lend a hand?

Regards,

Spencer

Logfile of HijackThis v1.99.1
Scan saved at 3:03:46 PM, on 1/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\McAfee.com\VSO\McVSEscn.exe
C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINDOWS\System32\hpha2mon.exe
O4 - HKLM\..\Run: [hpfsched] C:\WINDOWS\hpfsched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: MasterCook: Select Image - C:\Program Files\MasterCook 8\Web\MCIEContext.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc...aploader_v6.cab
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

BC AdBot (Login to Remove)

 


m

#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:02 PM

Posted 27 January 2006 - 05:13 PM

To use RootKit Revealer please make sure you are logged in as an Administrator to the computer.
  • Please download and unzip Rootkit Revealer to your desktop.
  • Please leave the defaults set as they are to:
    • Hide NTFS Metadata Files: this option is on by default
    • Scan Registry: this option is on by default.
  • Launch rootkit revealer on the system and press the Scan button.
    RootkitRevealer scans the system reporting its actions in a status area at the bottom of its window and noting discrepancies in the output list. It may take a long time please disconnect from the internet and leave the PC to be scanned until it is finished.
  • The log can be very large please edit out the items in the following folders in the log : C:\RECYCLER\NPROTECT and C:\System Volume Information, if in the log, before posting it.
  • Please post the balance of the log here in this thread using Add Reply (please double check that it has all been posted as it may be too long for one post)]
Then Download and Save blacklite to your desktop.
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
Double-click blbeta.exe then accept the agreement.
leave [X]scan through windows explorer checked,
click > scan then > next,
You'll see a list of all items found.
Don't choose for rename yet! I want to see the log first, because legit items can also be present there... like "wbemtest.exe"
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste this log along with the rootkit revealer log.

#3 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:02 PM

Posted 27 January 2006 - 05:14 PM

If you get the task manager up, and click on file then run, and type explorer.exe and press enter. Does your desktop appear?

#4 Clayboy

Clayboy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:02 PM

Posted 28 January 2006 - 01:56 PM

No Dice on the explorer.exe for it want's a file path. I'm working the other requests now.

#5 Clayboy

Clayboy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:02 PM

Posted 28 January 2006 - 03:31 PM

RootKitReveal

I forgot to disconnect from internet. My apologies. Log below.

C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\0NZJM8DT\indent[1].gif 1/28/2006 1:54 PM 96 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\0NZJM8DT\index[1].gif 1/28/2006 1:55 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\0NZJM8DT\tongue[1].gif 1/28/2006 1:54 PM 698 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\3JTFB5GK\palette[1].htm 1/28/2006 1:54 PM 7.51 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\3JTFB5GK\rte_tile[1].gif 1/28/2006 1:54 PM 259 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\3JTFB5GK\sad[1].gif 1/28/2006 1:54 PM 698 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\6VQFMD23\icon5[1].gif 1/28/2006 1:54 PM 672 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\6VQFMD23\wacko[1].gif 1/28/2006 1:54 PM 946 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\7JH7J5SG\icon8[1].gif 1/28/2006 1:54 PM 677 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\7JH7J5SG\w00t[1].gif 1/28/2006 1:54 PM 588 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\89MF4TUR\clapping[1].gif 1/28/2006 1:54 PM 4.68 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\89MF4TUR\cold[1].gif 1/28/2006 1:54 PM 1.54 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\AHMDI18J\dance[1].gif 1/28/2006 1:54 PM 10.83 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\AHMDI18J\hysterical[1].gif 1/28/2006 1:54 PM 14.33 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\CPUVCLI3\code[1].gif 1/28/2006 1:54 PM 139 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\CXQ3WDQ7\right_just[1].gif 1/28/2006 1:54 PM 76 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\G773E4HP\cool[1].gif 1/28/2006 1:54 PM 696 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\G773E4HP\icon12[1].gif 1/28/2006 1:54 PM 1.04 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HJJ06G5R\bold[1].gif 1/28/2006 1:54 PM 81 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HJJ06G5R\index[1].gif 1/28/2006 2:04 PM 43 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HV3LF9BW\blink[1].gif 1/28/2006 1:54 PM 1.06 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HV3LF9BW\closeall[1].gif 1/28/2006 1:54 PM 351 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HV3LF9BW\index[1].gif 1/28/2006 1:35 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HV3LF9BW\index[1].php 1/28/2006 1:55 PM 14.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\HV3LF9BW\index[3].htm 1/28/2006 1:55 PM 61.28 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\IUBJLWBB\icon4[1].gif 1/28/2006 1:54 PM 671 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\IUBJLWBB\laugh[1].gif 1/28/2006 1:54 PM 690 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\J2BARBQW\strike[1].gif 1/28/2006 1:54 PM 878 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\J6DJX58E\cheff[1].gif 1/28/2006 1:54 PM 736 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\J6DJX58E\underline[1].gif 1/28/2006 1:54 PM 93 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\KL2RC9A3\numbered_list[1].gif 1/28/2006 1:54 PM 90 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\U93SLKBQ\icon6[1].gif 1/28/2006 1:54 PM 666 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\U93SLKBQ\whistling[1].gif 1/28/2006 1:54 PM 1.20 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UBUVUH6R\icon14[1].gif 1/28/2006 1:54 PM 1.08 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UBUVUH6R\index[1].htm 1/28/2006 1:54 PM 49.90 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UBUVUH6R\topic42460[1].html 1/28/2006 1:35 PM 14.52 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UXVKDOVM\dry[1].gif 1/28/2006 1:54 PM 696 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UXVKDOVM\index[4].htm 1/28/2006 2:04 PM 61.16 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\UXVKDOVM\ipb_editor_std[1].js 1/28/2006 1:54 PM 16.92 KB Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\YXGHELWL\icon1[1].gif 1/28/2006 1:54 PM 672 bytes Hidden from Windows API.
C:\Documents and Settings\Kellie Blanton\Local Settings\Temporary Internet Files\Content.IE5\YXGHELWL\in_love[1].gif 1/28/2006 1:54 PM 13.00 KB Hidden from Windows API.

Blacklight states that "Windows Explorer was not found for the current user."

That's twice now. I assume I need to install windows explorer again? Where can I get it?

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:02 PM

Posted 28 January 2006 - 05:44 PM

IN the run field type c:\windows\explorer.exe

#7 Clayboy

Clayboy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:02 PM

Posted 29 January 2006 - 09:15 AM

IN the run field type c:\windows\explorer.exe


No explorer.exe at that location. Can I download and reinstall it from Microsoft?

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:02 PM

Posted 29 January 2006 - 11:11 AM

Download it from here:

http://www.bleepingcomputer.com/files/winfiles/explorer.exe and save it in your c:\windows folder.

Then reboot and tell me if you get your desktop.

#9 Clayboy

Clayboy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:02 PM

Posted 29 January 2006 - 12:29 PM

Yeah! Thank you. The desktop interface appears and operates!

I did get a couple errors though. One said DLL failed. The other was in reference Hotkey. How do I figure out which DLL is failing?

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:02 PM

Posted 29 January 2006 - 10:56 PM

What exactly are the errors you are receiving?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users