Solved Explorer.exe keeps restarting and there is always a BSOD

Xiomax

New Member
Messages
3
Hello fine people of eightforums.com,

Since a day or two, whenever i try to restart, shut down or log off my laptop i get without fail a BSOD with CRITICAL_PROCESS_DIED. Another related symptom is the fact that my explorer.exe constantly keeps crashing at fixed intervals (every 30 - 60 seconds) and then restarts again. This happens automatically even when i am not touching the computer, i have tried booting in safe mode but the same thing keeps happening there as well. I have tried to refresh my windows installation where i just get a error message stating nothing has been changed. My System restore points have been "mysteriously" deleted so i am really suspecting a virus which is going rampant on my beloved laptop.

I am now running as many virus scanners as i can but any help and insight would be greatly appreciated.

Thanks!

SF Diagnostic Tool:
https://www.dropbox.com/sh/8nnsjk6thvnxal7/AADHsSeUSpgANn2_mxtUN4Bva/SF_28-07-2014.zip
 

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    Lenovo Y500
All recent BSOD's were caused by a program called: dwiIk.exe and I don't know what it is. Google search does not have any information on this file.

EDIT: Perhaps, you might want to search and locate where it is then disable it to see if the problem goes away.
 

My Computer

System One

  • OS
    8.1x64PWMC Ubuntu14.04x64 MintMate17x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Home Brewed
    CPU
    I7 4970K OC'ed @4.7 GHz
    Motherboard
    MSI-Z97
    Memory
    16 GB G-Skill Trident X @2400MHZ
    Graphics Card(s)
    NVIDIA GeForce GTS 450
    Sound Card
    X-Fi Titanium Fatal1ty Professional Series
    Monitor(s) Displays
    Dual HP-W2408
    Screen Resolution
    1920X1200
    Hard Drives
    256 GB M2 sm951, (2) 500GB 850EVO, 5TB, 2 TB Seagate
    PSU
    Antec 850W
    Case
    Antec 1200
    Cooling
    Danger Den H20
    Keyboard
    Logitech
    Mouse
    Logitech Performance Mouse MX
    Internet Speed
    35/12mbps
    Browser
    Firefox
Hi Xiomax,

In addition to what Topgundcp has asked you to do, could you please run the GMER from this **link** and post back the log file?


Furthermore, the mysterious removal of the Shadow Volume Copies (System Restores) has got me thinking. Did you recently open any attachment in a mail from Symantec/Fedex/UPS/Money Receipt or anything like that?

Could you please open up the Run Prompt (Windows Key + R) and type in "regedit". Once opened, check the following entries :-
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker_<version_number>"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker_<version_number"
 

My Computer

System One

  • OS
    Windows 8.1 Industry Pro B-)
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Core I5 2430M @ 2.4GHz
    Memory
    8 GB DDR3 @ 1600MHz Dual Channel ^_^
    Graphics Card(s)
    Intel HD 3000 B-)
    Screen Resolution
    1366x768
    Hard Drives
    Toshiba 500 GB
    Browser
    Google Chrome
    Antivirus
    Windows Defender & Common Sense!
Thank you for the fast responses!

All recent BSOD's were caused by a program called: dwiIk.exe and I don't know what it is. Google search does not have any information on this file.

EDIT: Perhaps, you might want to search and locate where it is then disable it to see if the problem goes away.

After i had finished a full scan with Kaspersky it showed indeed that this was the case. It has since been resolved and the computer now shuts down, logs off and restarts normally so that is an big improvement. Only the constant restarting off explorer.exe remains to be the issue now.


Hi Xiomax,

In addition to what Topgundcp has asked you to do, could you please run the GMER from this **link** and post back the log file?

Link to log: https://db.tt/knxCWzEt

After starting the program it showed me this error message and i wasn't sure if this would interfere with the results. The scan did however complete successfully:
View attachment 47796

Furthermore, the mysterious removal of the Shadow Volume Copies (System Restores) has got me thinking. Did you recently open any attachment in a mail from Symantec/Fedex/UPS/Money Receipt or anything like that?

No nothing in particular like that as far as i can remember.

Could you please open up the Run Prompt (Windows Key + R) and type in "regedit". Once opened, check the following entries :-
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker_<version_number>"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker_<version_number"

None of the keys you mentiond seem to be present but i did recongize the name "Crypto" being used in a list of files currently opened and used by explorer.exe. I am also a bit worried about files coming from "C:\Windows\System32\en-US" and having normal names but then ending in ".mui" that may be related.

View attachment 47798
 
Last edited:

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    Lenovo Y500
That is fine mate. Just wanted to ensure that it is not something else :)

You could run the System File Checker using this guide and see if it solves your problem or not :-

How To Use SFC Scannow to Repair Windows System Files


By the way are you still getting BSOD's?
 

My Computer

System One

  • OS
    Windows 8.1 Industry Pro B-)
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Core I5 2430M @ 2.4GHz
    Memory
    8 GB DDR3 @ 1600MHz Dual Channel ^_^
    Graphics Card(s)
    Intel HD 3000 B-)
    Screen Resolution
    1366x768
    Hard Drives
    Toshiba 500 GB
    Browser
    Google Chrome
    Antivirus
    Windows Defender & Common Sense!
I went ahead and googled what CryptoProvider.dll was doing and i finally got a forumpost with exactly the same symptoms.

explorer.exe crashing every few seconds - Microsoft Community

I deleted the file and the folder: "C:\ProgramData\Microsoft\Crypto" and the problem has been solved!

Again thank you very much guys, without your suggestions i wouldn't have known where to look for the solution!
 

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    Laptop
    System Manufacturer/Model
    Lenovo Y500
I went ahead and googled what CryptoProvider.dll was doing and i finally got a forumpost with exactly the same symptoms.

explorer.exe crashing every few seconds - Microsoft Community

I deleted the file and the folder: "C:\ProgramData\Microsoft\Crypto" and the problem has been solved!

Again thank you very much guys, without your suggestions i wouldn't have known where to look for the solution!

Great to hear that you solved your problem ^_^.

I was just making sure that you were not infected by the CryptoLocker as it has been prevalent for a while now. Anyways good to see that you resolved and thanks for the rep ^_^.
 

My Computer

System One

  • OS
    Windows 8.1 Industry Pro B-)
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Core I5 2430M @ 2.4GHz
    Memory
    8 GB DDR3 @ 1600MHz Dual Channel ^_^
    Graphics Card(s)
    Intel HD 3000 B-)
    Screen Resolution
    1366x768
    Hard Drives
    Toshiba 500 GB
    Browser
    Google Chrome
    Antivirus
    Windows Defender & Common Sense!
Hi Xiomax ^_^,

Could you please do a favour by searching for a driver named - "ciiog.sys" in your system and report back your findings? It would help me add the information to the Driver Reference Table.

THANKS!
 

My Computer

System One

  • OS
    Windows 8.1 Industry Pro B-)
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Core I5 2430M @ 2.4GHz
    Memory
    8 GB DDR3 @ 1600MHz Dual Channel ^_^
    Graphics Card(s)
    Intel HD 3000 B-)
    Screen Resolution
    1366x768
    Hard Drives
    Toshiba 500 GB
    Browser
    Google Chrome
    Antivirus
    Windows Defender & Common Sense!
Back
Top