XP blank desktop – explorer.exe not loading (virut)

A friend of mine dropped off her Compaq laptop the other day, apparently it had been running slow and a friend of hers came round and “did stuff” to “sort it” – unfortunately it didn’t go to plan, and instead of the system performance improving as a result of the activity – it deteriorated to the stage where XP would display a blank desktop on startup (as in no taskbar, start menu, desktop shortcuts or anything).

So this was the state it was in when I got it. Here’s what I did:

Step 1: Get access to Windows Explorer
Hit ctrl-alt-delete – this only worked after leaving it alone for a couple of minutes after boot-up. Click “File>New Task (run) and type “explorer”. This brings up the windows desktop furniture.

Step 2: Find out why it isn’t loading
I wondered what her friend did.. I looked at the most recent installed apps in Programme files – there was an app called “TuneUp Utilities 2009″. A likely suspect I thought. In the wrong hands these tweak/tuneup utils can do more harm than good. I loaded up the app and undid all the “fixes”

Step 3: Check a little deeper
Restoring the TuneUp files didn’t solve the explorer.exe problem, so I figured that something else must be up with it. I suspected malware. I have rescued several Windows systems from malware (spyware, trojans etc) before using a great bit of software called MalwareBytes AntiMalware. I couldn’t get the faulty system to read the installer from my USB drive, so I had to burn it off onto CD. While I was doing that – I also stuck ‘FixShell‘ on there (a visual basic script that restores explorer.exe to the XP shell).

Step 4: Safe mode scanning
I restarted the PC and hit F8 repeatedly as the laptop started up, which brought up the XP menu with the option to load ’safe mode’. I did this and logged in as administrator (which for some reason had not appeared during normal startup). This time it loaded up with explorer.exe no problem. I ran MalwareBytes AntiMalware quick-scan and it picked up 27 items. Some were trojans, mentions of rootkit (eek) and other registry entries (including disabling security centre). I opted to ‘fix’ them all and restarted again as prompted (some nasty bits of malware can only be deleted on boot). This still did not fix the issue. I ran another scan just in case. It found a few more bits. Restart.

Step 5. Manual(ish) restore of explorer.exe
…. this is where it got quite interesting… after several unsuccessful attempts to restore command.exe, including creating a slipstreamed SP3 disc to run sfc /scannow – I finally installed Avast Antivirus Home Edition and did a boot time scan (AVG8 was already installed but I removed it, finally realising it hadn’t done its job). Avast picked up lots of win32:JunkPoly infections. JunkPoly is Avast speak for Virut.

Virut is bad.

Very bad.

Worse than bad – it’s terminal.

Format and reinstall is the only option. Backing up is risky.

So now I need to get the photos off, scan them thoroughly and format the hard-drive and reinstall XP.

It probably came from a P2P service, somehow got passed AVG8 (outdated virus def probably), and started infecting the system with all kinds of malware.

Just downloading Ubuntu now – will attempt to back the data up tomorrow…

Give me your favourite quotes

I have been using a great little Wordpress plug-in called ‘Quotes Collection‘ on this blog – it’s great for grabbing those quotes you see popping up over the web and adding them to your blog. It is my favourite aspect of my own blog actually – I like being inspired, challenged or reminded of important concepts and values by great thinkers.

You can get a sample of them by clicking on ‘Next Quote’ over there on the left- it doesn’t need to reload the page due to some javascript trickery (and you should see a non-javascript degraded version if you you don’t have js turned on).

Anyway – I want your quotes! What is your favourite quote? What makes a good quote?

If you have a favourite quote that covers anything in the category/tag cloud – please post them here and I will add them to my quotes collection… and others can grab them too.

Firefox 3.0.1 location url bar autocomplete broken (and rss live feed bookmarks)

My favourite web browser – Mozilla’s Firefox, has recently begun to cause consternation – only on my work PC. On the laptop it is fine. There are a gazillion blog/forum posts complaining about the new functionality of said URL bar, but so far I haven’t found anyone else describing the same issue as myself and several of my work colleagues.

This is what it looks like:

My broken Firefox 3

My broken Firefox 3

So – it looks like the autocomplete is ‘working’ (as in it brings up the icons for the pages) but it is not displaying the text – which makes it pretty useless. Even more odd is the fact that my Live Bookmarks (RSS) are no longer displaying either.

I tried everything (safe mode, delete localstore.rdf, new profile etc as per the Firefox Standard Diagnostic) ending in a complete and utter fresh install. A few of these seemed to fix it but on restart – the problem returned…

Another one of those annoyances I thought I would share just in case anyone else out there has the same/similar issue.

I will keep you updated as to whether a fix is found.

UPDATE: Today’s 3.0.2 update didn’t fix it either… well – it did until system restart (just like all the other installs I performed). Another thing I noticed today is that it doesn’t reload tabs when it does a browser restart, also ‘recently closed tabs’ is greyed out.

I am thinking that my initial conviction that it is caused by Group Policy at work is still the most likely… although our IT guy says he has the same problem at home (but there is a connection there ;-) )

UPDATE: Today’s 3.0.3 update didn’t fix anything, although I notice that if I right click the url bar (where the star is) and select ‘customize…’ then click ‘Done’ – all my live bookmark feeds in the toolbar re-appear (until the next restart). Hmmmm…

Wireless trouble after installing XP SP3

I finally succumbed to installing Windows XP Service Pack 3 on my Asus F5RL laptop yesterday… it all seemed to go well, until I was surfing around the web and noticed that my internet connectivity dropped out (but my wireless connection to the router seemed fine). I tried an ipconfig /flushdns in the command prompt, but that didn’t help. In the end I managed to temporarily get back on the internet by ‘repairing’ my wireless connection. It seems to happen randomly every hour or so – I haven’t yet discovered a pattern.

This is what Firefox tells me:

Connection Interrupted

The document contains no data

The network link was interrupted while negotiating a connection. Please try again.

It doesn’t actually help that I had some trouble with my ADSL the evening before the SP3 install, that’s just muddying the waters. That turned out to be fixed by unplugging the telephone lead from the router for no less that 70 mins – but not before the muppets at plus.net made me reset my router back to factory settings of course. I wish they would rip that page out of their crib sheets where it says “Get the numpty customer to reset their router and reinstall their operating system before you actually listen to their description of the problem” ;)

Anyway – my next step at trying to fix the annoying SP3 issue (which, incidentally – I recommend you do not install unless you have read find a thread here with a cluster of folks who had similar symptoms… no real solution there – the reset the Winsock Catalog comment looks promising – I might try that if I can replicate the error after I changed the DNS settings to point to the ISPs DNS server, rather than the routers IP address.

Are you with me so far? I will be back in a bit with some updates – I need to see if I get the error again.

UPDATE – I got the error again. Clicked ‘try again’ and it loaded the page up… mmm

UPDATE – I also found this which discusses possible issues with WPA-PSK and TKIP… great!

UPDATE: I changed the wireless channel on my router a couple of days ago from ch 13 to ch 11, and haven’t had any issues since. As far I am concerned – this is fixed.