New Virus or XP Pro Bug?

J

JimC

For the 3rd time in a month I have had to fix the exact same XP Pro problem.

It has the characteristics of both a hardware/software glitch and a hacker's
clever trick. Here is the story...

Suddenly, on bootup an Application Error dialog states that Explorer.Exe
failed to initialize (error 0xc000006), which results in a barren (blank)
screen and mouse cursor. Of course, Alt+Ctrl+Del brings up Task Manager...
and you can run anything from there (or launch Windows Explorer/PowerDesk to
make running stuff easier). However, many Users would not remember to
invoke Task Manager or know that you can run tasks from it.

When I run Chkdsk /R and reboot, Chkdsk reports only fixing bad sectors in
Uxtheme.Dll. However, this produces an endless cycle of automatic
re-booting after the fix (because the "fixed" Uxtheme.Dll is no good).
However, using the XP CD and the Recovery Console, you can break this cycle
by renaming %systemroot%\System32\Uxtheme.Dll. After this action,
Explorer.Exe again fails on startup, but you can then copy a good version of
Uxtheme.Dll from %systemroot%\ServicePackfiles\I386\ to
%systemroot%\System32\. This completely fixes things until the next date
when something/someone corrupts Uxtheme.Dll.

Has anyone had the same repeated experience (and does anyone know how
Uxtheme.Dll is getting clobbered)?

I am beginning to think some kind of purposeful mischief is at work because
of how the same file (Uxtheme.Dll) keeps getting clobbered... and because
this causes what appears to be a big problem (that really has a simple
solution)... the kind of trickery that a hacker might enjoy visiting upon
others. Most folks would probably send their PC in for service... and I was
LUCKY to find the simple fix.

Is there a way to find out what process is clobbering Uxtheme.Dll?

--Jim
 
J

Juan

Greetings:

Download "Process Explorer" from systernals.com.. it's freeware
and requires no registration.. install it and search for Uxtheme.dll in the
Find menu to see the processes running this dll.

This utility helps you see which files, registry keys and other objects
processes have open, which DLLs they have loaded, and more. This uniquely
powerful utility will even show you who owns each process. one of its
features is that it can show you which .dlls are being used by
applications.. and a lot more, its similar to the taskmanager but it gives
much more info..

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

http://www.sysinternals.com/

http://www.sysinternals.com/licensing.shtml



-------------------Original Message-----------------
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top