1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Msconfig/Startup runs and then disappears

Discussion in 'Virus & Other Malware Removal' started by WP.USER, Sep 12, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    Problem: The Wild Tangent Error Pop-up was solved on my desktop computer by using:

    START ---- RUN---type in msconfig-----then going to START-UP and unchecking the Wild Tangent File...... But.....

    Our Laptop has the same problem, which is an XP also.....we tried the above solution. The lap top has SPY Bot, and Ad Ware removal like my desktop computer, but now we have a new problem before we solve the Wild Tangent problem.

    And that is.......When we go to click the Start-up Tab in the System Configuration Ultilty which brings us to all the files on Start-up, we do see all the files but, the page disappears after about 5 seconds, it acts like it is timing out.

    This quick disappearing act does not give us a chance to find the file and unclick the Wild Tangent file to solve our problem.

    How do we fix the Start-up so it will last more than 5 seconds?

    Thanks for all your help!
     
  2. Dan O

    Dan O

    Joined:
    Feb 13, 1999
    Messages:
    8,974
    Try running Windows System File Checker (SFC), which repairs damaged and missing files. To execute it select Start/Run and type: SFC /SCANNOW
     
  3. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    I tried running Windows System File Checker: Start/Run and type: SFC /SCANNOW.

    It did check, because it took a long time to scan. Once it was finished, the little box disappeared. Was it suppose to do anything else?

    Anyway, I tried getting back into System Configuration Ultility to the Start-Up tab and it immediatly closes (I see the files for less than a second).

    Any other suggestions?

    Thanks for all your help.
     
  4. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    Bumping to the top....
     
  5. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Download Adaware Se from http://www.lavasoftusa.com/support/download/
    In Ad-aware click the Gear to go to the Settings area.
    The following items should be on a green check, not on a red X.
    Under the Scanning button:Scan within archives
    Under Memory & Registry, Check EVERYTHING
    In Check Drives & Folders, make sure all of your hard drives are selected
    Under the Advanced button, Check
    Move deleted files to recycle bin
    Include additional object information
    Include negligible object information
    Include environment information
    Under the defaults button Set the homepage you wish to have set as default.
    Under the tweak button
    Some of these may not be an available option, depending on your version of Ad-aware and your version of Windows. Do not be concerned if you cannot select a certain item.

    In Scanning Engine:Unload recognized processes during scanning
    Include info about ignored objects in logfile, if detected in scan
    Include basic Ad-aware settings in logfile
    Include additional Ad-aware settings in logfile
    Include used command line parameters in logfile
    In Cleaning Engine: XP/2000: Allow unloading explorer to unload shell extensions prior to deletion
    Let Windows remove files in use at next reboot
    UNCHECK: Automatically try to unregister objects prior to deletion
    Click Proceed to save these settings. When you would like to perform a "Full Scan," switch the scan mode from SmartScan to Custom
    _______________________________________________________________
    Create a folder on your hard drive somewhere like in "My Documents" and name it Hijackthis
    Download 'Hijack This to its own folder http://www.dotcomsecurity.org/downloads/HijackThis.exe
    Doubleclick HijackThis.exe, and hit "Scan".

    When the scan is finished, the "Scan" button will change into a "Save Log" button.
    Press that, save the log, load it in Notepad, and copy its contents here.

    Most of what it lists
    will be harmless or even essential, don't fix anything yet.
     
  6. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    I am slowly digesting all the information you provided.

    I did the Quick Reply early this morning and sent a message, but I do not see my message! :( Now....I have to remember all the information I meant to say this morning.

    Long story made short....My biggest problem was trying to find Notepad on my Hard Drive. I know how to find Notepad when I go to Start, then Assessories, then Notepad, but.....How do you find it from the Hard Drive?

    I looked and looked.....but, could not find Notepad when looking for it from the hard drive. Help! I know it is there! Can you please tell me how to locate Notepad when looking for it from the Hard Drive? Then.....I can show you my files.

    Thanks for all you help....
     
  7. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    Bumping to the Top.

    I did do the SCAN for HijacK This....but, could not figure out how to Save to Notepad.

    Also, when looking over the files, I did see 3 Wild Tangent Files.

    Please tell me how to save this file so you can see them.

    Thanks for all your help.
     
  8. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    Logfile of HijackThis v1.98.2
    Scan saved at 10:58:10 AM, on 9/15/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\System32\ScsiAccess.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\smsc.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\WINDOWS\System32\svxhost.exe
    C:\WINDOWS\System32\svchosts.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
    C:\WINDOWS\System32\WINBOOT32.EXE
    C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
    C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    C:\Program Files\EzButton System V1.0\EzButton.exe
    C:\Documents and Settings\Rick's Place\My Documents\New Folder\HijackThis.exe
    C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.averatec.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [QBCD Autorun] D:\autorun.exe restart TIMER_SEQUENCE first
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [Microsoft-Updates] svxhost.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [Win32 USB2 Driver] smsc.exe
    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\zuwjkms.exe
    O4 - HKLM\..\Run: [Microsoft Restore] scrgrd.exe
    O4 - HKLM\..\Run: [Windows Config] svchosts.exe
    O4 - HKLM\..\Run: [Reg Services] WINBOOT32.EXE
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\RunServices: [Microsoft-Updates] svxhost.exe
    O4 - HKLM\..\RunServices: [Win32 USB2 Driver] smsc.exe
    O4 - HKLM\..\RunServices: [Microsoft Restore] scrgrd.exe
    O4 - HKLM\..\RunServices: [Windows Config] svchosts.exe
    O4 - HKLM\..\RunServices: [Reg Services] WINBOOT32.EXE
    O4 - HKLM\..\RunOnce: [Win32 USB2 Driver] smsc.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
    O4 - HKCU\..\Run: [Microsoft Restore] scrgrd.exe
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
    O4 - HKCU\..\RunOnce: [Win32 USB2 Driver] smsc.exe
    O4 - Startup: EzButton System.lnk = C:\Program Files\EzButton System V1.0\EzButton.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094000918477
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DAFAD2DA-A3A0-44D6-AE9C-3E3131A46353}: NameServer = 207.69.188.187 207.69.188.186
     
  9. WP.USER

    WP.USER Thread Starter

    Joined:
    Sep 11, 2004
    Messages:
    19
    BuMpInG.....To.....THe.....ToP
     
  10. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Rescan once again now with hijack then insert a check next to each of the following then close all browser windows and click "fix checked"

    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background

    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot

    O4 - HKLM\..\Run: [Microsoft-Updates] svxhost.exe

    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain

    O4 - HKLM\..\Run: [Win32 USB2 Driver] smsc.exe

    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\zuwjkms.exe

    O4 - HKLM\..\Run: [Microsoft Restore] scrgrd.exe

    O4 - HKLM\..\Run: [Windows Config] svchosts.exe

    O4 - HKLM\..\Run: [Reg Services] WINBOOT32.EXE

    O4 - HKLM\..\RunServices: [Microsoft-Updates] svxhost.exe

    O4 - HKLM\..\RunServices: [Win32 USB2 Driver] smsc.exe

    O4 - HKLM\..\RunServices: [Microsoft Restore] scrgrd.exe

    O4 - HKLM\..\RunServices: [Windows Config] svchosts.exe

    O4 - HKLM\..\RunServices: [Reg Services] WINBOOT32.EXE

    O4 - HKLM\..\RunOnce: [Win32 USB2 Driver] smsc.exe

    O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe

    O4 - HKCU\..\Run: [Microsoft Restore] scrgrd.exe

    O4 - HKCU\..\RunOnce: [Win32 USB2 Driver] smsc.exe


    Now set your system to show hidden files and folders http://dotcomsecurity.org/forums/index.php?showtopic=57


    reboot into safe mode http://dotcomsecurity.org/forums/index.php?showtopic=55


    Open windows explorer, find then delete:
    C:\WINDOWS\System32\zuwjkms.exe
    C:\Program Files\WildTangent
    C:\WINDOWS\System32\svxhost.exe
    C:\WINDOWS\System32\WINBOOT32.EXE

    Reboot, rescan with hijack then post an updated logfile.
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/273230

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice