![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 440,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer
Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Oct 2008
Posts: 3
OS: XP
|
[SOLVED] Explorer.exe crashing when closing folders
Hi I'm new to tech support forums so please be patient if I have missed anything, I'll try to follow the rules as best I can...
I have recently come up with a problem that whenever I close ANY folder (windows explorer) explorer.exe will crash and restart itself. I have done some troubleshooting to help identify the cause of the error but haven't been able to come up with anything. I haven't been able to link any system changes (hardware, software installations) to the time the problem started. I am running Win XP Pro SP3 with IE 7 Here is a copy of two of the errors displayed from the Event Viewer: Event Type: Error Event Source: Application Error Event Category: None Event ID: 1000 Date: 22/10/2008 Time: 4:20:33 PM User: N/A Computer: ANGISPORTA Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x016216ce. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Data: 0000: 41 70 70 6c 69 63 61 74 Applicat 0008: 69 6f 6e 20 46 61 69 6c ion Fail 0010: 75 72 65 20 20 65 78 70 ure exp 0018: 6c 6f 72 65 72 2e 65 78 lorer.ex 0020: 65 20 36 2e 30 2e 32 39 e 6.0.29 0028: 30 30 2e 35 35 31 32 20 00.5512 0030: 69 6e 20 75 6e 6b 6e 6f in unkno 0038: 77 6e 20 30 2e 30 2e 30 wn 0.0.0 0040: 2e 30 20 61 74 20 6f 66 .0 at of 0048: 66 73 65 74 20 30 31 36 fset 016 0050: 32 31 36 63 65 0d 0a 216ce.. Event Type: Error Event Source: Application Error Event Category: None Event ID: 1000 Date: 22/10/2008 Time: 6:25:03 PM User: N/A Computer: ANGISPORTA Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x033616ce. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Data: 0000: 41 70 70 6c 69 63 61 74 Applicat 0008: 69 6f 6e 20 46 61 69 6c ion Fail 0010: 75 72 65 20 20 65 78 70 ure exp 0018: 6c 6f 72 65 72 2e 65 78 lorer.ex 0020: 65 20 36 2e 30 2e 32 39 e 6.0.29 0028: 30 30 2e 35 35 31 32 20 00.5512 0030: 69 6e 20 75 6e 6b 6e 6f in unkno 0038: 77 6e 20 30 2e 30 2e 30 wn 0.0.0 0040: 2e 30 20 61 74 20 6f 66 .0 at of 0048: 66 73 65 74 20 30 33 33 fset 033 0050: 36 31 36 63 65 0d 0a 616ce.. Troubleshooting Steps Performed: * Boot to safe mode - Problem DOES NOT occur! * Disable all startup items in msconfig - Problem still DOES occur * Checked option - Tools/Folder Options/View/ Launch folder windows in a separate process - Problem ONLY occurs while closing Recycling Bin (as far as I can tell) * Disabled DEP for Windows Explorer - System Properties\Advanced\Performance Settings\Data Execution Prevention - Problem still DOES occur * Ran sfc /scannow & Rebooted - Problem still DOES occur * Ran AntiVirus scan with Avast AV - No viruses detected * Cleaned Registry entries with RegCure - Removed detected entries (Empty reg keys, invalid paths) * Ran Spyware scan with SuperAntiSpyware, Malwarebytes Anti-Malware, - No spyware detected: Malwarebytes' Anti-Malware 1.29 Database version: 1304 Windows 5.1.2600 Service Pack 3 22/10/2008 5:46:09 PM mbam-log-2008-10-22 (17-46-09).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 81822 Time elapsed: 21 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) * Ran Online Scanner from Kaspersky - No Viruses detected: KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, October 22, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, October 22, 2008 06:24:05 Records in database: 1334152 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Files scanned 44814 Threat name 0 Infected objects 0 Suspicious objects 0 Duration of the scan 00:54:58 No malware has been detected. The scan area is clean. The selected area was scanned. All scans were performed after ensuring all Windows and definition updates were current * Followed 5 steps per POST instructions - System not showing any spyware related program in Add/Remove Programs * Installed protection software Spyware Blaster, IE-SPYAD & ZonedOut * Ran Online Scanner from Panda - No viruses detected: ![]() HighJack This log in Normal Boot Mode: (problem occurs) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:33:27 PM, on 22/10/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Applications\Avast AntiVirus\aswUpdSv.exe C:\Program Files\Internet Applications\Avast AntiVirus\ashServ.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Internet Applications\Avast AntiVirus\ashWebSv.exe C:\PROGRA~1\INTERN~2\AVASTA~1\ashDisp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Utility Applications\HiJack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com.au R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Internet Applications\Free Download Manager\iefdm2.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\INTERN~2\AVASTA~1\ashDisp.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1224664102156 O17 - HKLM\System\CCS\Services\Tcpip\..\{336B624E-B27A-43DE-B5E5-53D72C94ABA1}: NameServer = 192.168.0.10 O17 - HKLM\System\CCS\Services\Tcpip\..\{86A3A74B-8CE3-4A9B-B1BC-D30A010615B1}: NameServer = 192.168.0.4 O17 - HKLM\System\CS1\Services\Tcpip\..\{336B624E-B27A-43DE-B5E5-53D72C94ABA1}: NameServer = 192.168.0.10 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\Utility Applications\Super AntiSpyware\SASWINLO.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\ashServ.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\ashWebSv.exe -- End of file - 5524 bytes HighJack This log in Safe Boot Mode with Networking: (problem doesn't occur) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:40:16 PM, on 22/10/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Utility Applications\HiJack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com.au R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Internet Applications\Free Download Manager\iefdm2.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\INTERN~2\AVASTA~1\ashDisp.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1224664102156 O17 - HKLM\System\CCS\Services\Tcpip\..\{336B624E-B27A-43DE-B5E5-53D72C94ABA1}: NameServer = 192.168.0.10 O17 - HKLM\System\CCS\Services\Tcpip\..\{86A3A74B-8CE3-4A9B-B1BC-D30A010615B1}: NameServer = 192.168.0.4 O17 - HKLM\System\CS1\Services\Tcpip\..\{336B624E-B27A-43DE-B5E5-53D72C94ABA1}: NameServer = 192.168.0.10 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\Utility Applications\Super AntiSpyware\SASWINLO.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\ashServ.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Internet Applications\Avast AntiVirus\ashWebSv.exe -- End of file - 4987 bytes Help! Can anyone please offer assistance to ensure this isn't a malware / spyware infection? As far as I can tell it looks clean... Currently the problem only occurs when closing the recycling bin but I'm not sure the steps I have taken to get it to work this far are just a bandaid fix. Otherwise if anyone can refer me to the correct place to post I would be grateful. |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2008
Posts: 3
OS: XP
|
Re: Explorer.exe crashing when closing folders
Not to worry i just solved the problem!!!
Thanks to http://www.helpwithwindows.com/techf...r-crashes.html for the reference to ShellExView freeware My problem was being caused by a 3rd party shell extension (right click menu item) tracked back to a program called Free Download Manager ***O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Internet Applications\Free Download Manager\dllink.htm*** After uninstalling this program the shell extension was removed altogether resolving my issue. I hope this information may be of use to others with Explorer crashes - I found the above website a great source of information. :) |
|
|
|
|
|
#4 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 30,480
OS: WinXP Home, Vista, Windows 7 64bit
|
Re: [SOLVED] Explorer.exe crashing when closing folders
Hello pixiepi,
Our apologies for the oversight of your thread. Thank you for sharing this information. I'm sure it will help others who may be researching an issue such as yours. ![]() Take care, and surf safely.
__________________
Microsoft MVP - 2010 "It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
|
|
|
|
![]() |
| Thread Tools | |
|
|