Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

XP Explorer locked

Status
Not open for further replies.

qlark

Programmer
Jan 5, 2006
54
CA
I have been searching for a potential virus/trojan/spyware that might have caused an XP Pro machine to lock up Explorer.exe?

if I can't find a way back I think I may have to do a clean install any other alternatives would be welcome as there is 26G of files on this drive. I was going to do a Ghost image first then do a clean install then pull back the user directories but that is a task I would rather avoid if there is a solution out there to this problem.

It appears that Explorer.exe or one of its dependants is locking all users including safe mode from starting programs ... the mouse works and tasks can be started from a ctrl-alt-del task manager but the moment any app starts and requires an explorer shell the app hangs

Explorer also won't shut down when attempting a windows shutdown from the task manager ... it reports that Explorer.exe is not responding

This machine was loaded with XP Pro and was upgraded to SP1 then SP2 ... when I go and try to do a repair install the PRO cd reports that you are attempting to install an older version of XP and will not let me continue.

sfc /scannow (run from task manager) doesn't appear to reveal anything ... a NIS Scan (from cd) doesn't reveal any issues either

Not sure if there are any restoral points because I can't get into a recovery consol
 
SCF won't reveal anything, it will just automatically restore corrupt system files. NIS scan from cd won't pick up any viruses that were created since the cd was manufactured - could be a year or so out of date.

First, I'd try going in to msconfig and diabling all startup programs and all non-microsoft services and re-boot - see if you still have the problem.

If you can't do that, I'd try downloading SpyBot and Ad-aware and their definition files onto a cd from another machine and install and scan with them in safe mode.

If you can't do that, try removing the drive and installing it as a slave in another machine and scanning it that way with some good anitivirus and antispyware tools. Not as good because it won't scan the registry, but it may work.

 
Yes did the Msconfig thing ... not sure if spyboot will run as it requires a shell (explorer) if will try your idea of slaving the drive and attacking it with AV's etc.

Thanx
 
do a google search on insert and knoppix security. i have used these two live cd versions of linux to recover data, and i have read that they can be used to remove viruses from windows partitions, though you should use caution.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top