themed32.dll problem, help!

The CMD command when run should bring up a black window at: C:\Winnt

This is the command prompt window.

If it doesn't bring up the command window try the whole line in the Run window


Copy the EXPLORER.EXE by Right Clicking and paste it in the same folder. A file "Copy of EXPLORER.EXE" will be created in the folder. Now change the file name to your name.exe. For example, I renamed mine to "yourname.exe"
When you select copy and paste it in the same folder it will name it something like explore2.exe

I still don't quite get what you mean. In the window I'm supposed to have:

Microsoft Windows XP [Version 5.1.2600]

<C> Copyright 1985-2001 Microsoft Corp.

But am I meant to have:

C:\Documents and Settings\Megs>

or is that where I need to put EXPLORER.EXE. I'm a little confused about what you mean.

Right ok I see what you're on about, but whenever I enter in 'explorer.exe' it comes up with the theme32.dll error. And when I type in 'CD\C:\winnt' it comes up with 'the filename, directory name, or volume label syntax is incorrect'.

Please note any spaces in the commands, they need to be there.

You need to get to C:\WINNT

If the command prompt isn't at C:\WINNT then type in:

CD C:\Winnt (enter)

at C:\Winnt type in: CD C:\winnt\System32 (enter)

at: C:\winnt\System32 type in: ren C:\WINNT\system32\uxtheme.dll uxtheme.old (enter)

at C:\winnt\System32 type in: CD C:\WINNT\ServicePackFiles\i386 (enter)

at C:\WINNT\ServicePackFiles\i386 type in: copy C:\WINNT\ServicePackFiles\i386\uxtheme.dll C:\WINNT\system32 (enter)

You should see one file copied

Type in Exit and reboot

The copied file, is that 'Overwrite C:\WINNT\system32\uxtheme.dll? <Yes/No/ALL>:' ?

Is it meant to start up normally, I mean without the command prompt, or should something have come up before Windows loaded?

It should boot normal with the Windows Login.

You might have seen a black box (command Prompt} for a few seconds

Download Combofix from any of the links below but rename it to iexplore.exe before saving it to your desktop.

If need be, Download the tools needed to a flash drive or other USB device, and transfer them to the infected computer.


If combofix (iexplore.exe) won't run from the desktop, try running it from the USB device.

Link 1

Link 2 If using this link, Right Click and select Save As.

* IMPORTANT !!! Save iexplore.exe to your Desktop

Double click on the iexplore.exe ComboFix.exe & follow the prompts.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

  • Double click on iexplore.exe & follow the prompts.
    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7 or you don't have a internet connection.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

I have the desktop back and it seems to be working fine. Shall I still attach the log, if so what would it be called?

Copy iexplore.exe to your desktop and run it again.

Make sure you let it update

Does it need to update from the Internet because it still won't connect?
Run without the update

ComboFix 10-10-30.09 - Megs 11/03/2010 22:02:05.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1007.334 [GMT 0:00]

Running from: c:\documents and settings\Megs\Desktop\iexplore.exe.exe

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


c:\program files\Internet Explorer\complete.dat

c:\program files\Internet Explorer\dmlconf.dat

c:\program files\Internet Explorer\iexploreSrv.exe

c:\program files\Microsoft\DesktopLayer.exe

c:\program files\Microsoft\DesktopLayerSrv.exe








---- Previous Run -------



c:\documents and settings\standalone\Application Data\alot\Resources\BrowserSearch\images\favicon.ico

c:\documents and settings\standalone\Application Data\alot\Resources\Button_0\images\alot_logo_button.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_0\images\alot_logo_button.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_image_search.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_image_search.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_news_search.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_news_search.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_search_button.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_search_button.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_shop_search.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_shop_search.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_videos_search.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_videos_search.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_web_search.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_1\images\alot_web_search.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_10\images\3272_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_2\images\alot_configure.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_2\images\alot_configure.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_3\images\default_4106_default_2088_mrkt_hot_topic.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Button_3\images\default_4106_default_2088_mrkt_hot_topic.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_4\images\3998_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_5\images\3995_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_6\images\3999_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_7\images\2531_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_8\images\2718_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\Button_9\images\3970_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\contextMenu\images\alot_icon.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\contextMenu\images\alot_icon.png

c:\documents and settings\standalone\Application Data\alot\Resources\contextMenu\images\alot_logo_button.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\contextMenu\images\alot_logo_button.png

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\domains.dat

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\alot_brand.png

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\alot_splitter.png

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\discover.png

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\intro_popup.png

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\spinner.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_bottom.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnconfig0.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnconfig1.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnrefresh0.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_btnrefresh1.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_caption.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_error_close.bmp

c:\documents and settings\standalone\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp

c:\documents and settings\standalone\Application Data\alot\toolbar.xml

c:\documents and settings\standalone\Application Data\alot\toolbar.xml.backup

c:\documents and settings\standalone\Application Data\Apuhzi\abani.exe

c:\documents and settings\standalone\Application Data\Duva\awmy.exe

c:\documents and settings\standalone\Application Data\Gyud\qyeq.tmp

c:\documents and settings\standalone\Application Data\Gyud\qyeq.wed

c:\program files\Microsoft\DesktopLayer.exe



((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))





((((((((((((((((((((((((( Files Created from 2010-10-03 to 2010-11-03 )))))))))))))))))))))))))))))))


2010-11-03 18:22 . 2010-11-03 18:23 95744 ----a-w- c:\program files\Common Files\Microsoft Shared\Speech\sapisvrSrv.exe

2010-11-03 16:05 . 2010-11-03 16:56 95744 ----a-w- c:\program files\Windows Media Player\wmplayerSrv.exe

2010-11-01 18:12 . 2010-11-01 18:14 -------- d-----w- c:\program files\UK Truck Simulator

2010-10-31 21:25 . 2010-10-31 21:28 47104 ----a-w- c:\winnt\system32\mshtaSrv.exe

2010-10-31 16:05 . 2008-04-14 00:12 221184 ----a-w- c:\winnt\system32\wmpns.dll

2010-10-31 15:42 . 2010-10-31 15:42 -------- d-----w- C:\32788R22FWJFW.1.tmp

2010-10-31 11:53 . 2010-10-31 11:53 47104 ----a-w- c:\winnt\system32\sstext3dSrv.exe

2010-10-30 12:22 . 2008-04-14 00:12 218624 ----a-w- C:\uxtheme.dll

2010-10-30 11:38 . 2010-11-03 16:16 47104 ----a-w- c:\winnt\system32\verclsidSrv.exe

2010-10-29 20:48 . 2010-10-31 12:07 -------- d-----w- c:\documents and settings\Megs

2010-10-27 16:53 . 2010-10-27 16:53 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp

2010-10-27 16:47 . 2010-10-27 16:47 -------- d-----w- c:\documents and settings\standalone\Application Data\Xiinpa

2010-10-27 16:47 . 2010-10-27 16:48 -------- d-----w- c:\program files\windows

2010-10-27 16:47 . 2010-10-27 16:47 -------- d-----w- c:\program files\riv87

2010-10-27 15:28 . 2007-04-04 18:53 81768 ----a-w- c:\winnt\system32\xinput1_3.dll

2010-10-27 15:26 . 2010-10-27 15:26 -------- d-----w- c:\winnt\Logs

2010-10-25 18:32 . 2010-10-25 18:32 -------- d-----w- c:\program files\NCH Swift Sound

2010-10-23 12:09 . 2009-02-26 12:06 521080 ----a-w- C:\POWERPNT.EXE


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2010-10-29 18:08 . 2004-08-04 12:00 120192 ----a-w- c:\winnt\system32\drivers\pcmcia.sys

2010-10-21 18:47 . 2009-10-03 13:47 210944 ----a-w- C:\UNWISE.EXE


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown



"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-09 39408]


"Synchronization Manager"="mobsync.exe" [2008-04-14 143360]

"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2010-10-14 114688]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-10-21 471040]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 66680]

"vptray"="c:\progra~1\SYMANT~2\VPTray.exe" [2004-07-20 124112]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"SoundMan"="SOUNDMAN.EXE" [2003-03-27 53248]

"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2010-10-21 917504]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-10 149280]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]


"internat.exe"="internat.exe" [2002-07-24 20752]


"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2008-04-14 214528]

"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2004-08-04 44544]

c:\documents and settings\standalone\Start Menu\Programs\Startup\

WePrint Server.lnk - c:\program files\WePrint\WePrint Server.exe [2010-7-2 2268672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 196608]

hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]



"DisableNotifications"= 1 (0x1)



"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe: RAPI Manager

"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe: Connection Manager

"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe: Application

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\WePrint\\WePrint Server.exe"=


"26675:TCP"= 26675:TCP: Service

R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [7/1/2010 11:07 59240]

R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [7/1/2010 11:07 166632]

R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [7/1/2010 11:07 840936]

R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\winnt\system32\drivers\A311.sys [7/6/2004 08:12 33335]

R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\winnt\system32\drivers\A310.sys [7/6/2004 08:12 33335]

S1 mkh2de0;mkh2de0;c:\winnt\system32\drivers\mkh2de0.sys [2/13/2010 15:00 0]

S1 pmk70ea;pmk70ea;c:\winnt\system32\drivers\pmk70ea.sys [2/5/2010 17:52 0]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/26/2009 16:34 135664]

S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/12/2004 14:18 169192]

S3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [7/6/2004 07:48 49776]


Contents of the 'Scheduled Tasks' folder

2010-11-03 c:\winnt\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]

2010-11-03 c:\winnt\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-26 16:34]

2010-11-03 c:\winnt\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-26 16:34]

2010-11-02 c:\winnt\Tasks\Norton Security Scan for standalone.job

- c:\program files\Norton Security Scan\Engine\\Nss.exe [2010-07-03 08:48]



------- Supplementary Scan -------


uStart Page = hxxp://www.viglen.co.uk

IE: Add to Google Photos Screensa&ver - c:\winnt\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000


- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)

HKLM-Run-Malwarebytes Anti-Malware (rootkit-scan) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe

HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe


AddRemove-Macromedia Shockwave Player - c:\winnt\system32\Macromed\SHOCKW~1\UNWISE.EXE


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-11-03 22:21

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0



--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(432)




Completion time: 2010-11-03 22:29:50

ComboFix-quarantined-files.txt 2010-11-03 22:29

Pre-Run: 3,701,819,392 bytes free

Post-Run: 3,649,264,128 bytes free

- - End Of File - - 78D7CB8D06323C2843C25A4B4C3EDBBC

Try this from Taskmanager

File > New Task

Type in:

copy c:\uxtheme.dll c:\winnt\system32

Windows will prompt you:

Overwrite c:\winnt\system32\uxtheme.dll? (Yes/No/All)

type in Yes

