1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Run-time error 53

Discussion in 'Virus & Other Malware Removal' started by Leon Corcora, Feb 9, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. Leon Corcora

    Leon Corcora Thread Starter

    Joined:
    Feb 9, 2003
    Messages:
    2
    I recently downloaded Avast32 and it found that I had a virus in C:\WINNT\System32\explore.exe
    WIN32 Trojan-gen (upx)
    As one of the options, I deleted the file. No more Virus's were found. However, when I boot up Windows 2000, I get the following error msg. Project 1 Run-time error 53 file not found. I suspect since I deleted the file that was infected, I now have the run-time error. I can continue everything runs normally.. I was wondering how to replace the file that was infected or eliminate
    the error msg. Regards, Leon Corcoran
     
  2. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    Welcome to TSG, Leon. The error may be the result of something else left on the system. The infected file was not a legitimate windows one originally.

    Let's see you current configuration and maybe we can offer some troubleshooting suggestions. Get the StartupList application from the site below, unzip and run it. Then copy/paste the results to a reply.

    http://www.lurkhere.com/~nicefiles/

    It sounds like the error is associated with something called "Project 1", whatever that is. Perhaps a registry entry left behind that referenced the infected file.
     
  3. Leon Corcora

    Leon Corcora Thread Starter

    Joined:
    Feb 9, 2003
    Messages:
    2
    StartupList report, 2/9/2003, 8:05:56 PM
    StartupList version: 1.51
    Started from : C:\Startup List\StartupList.EXE
    Detected: Windows 2000 SP3 (WinNT 5.00.2195)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\Ati2evxx.exe
    c:\ANTIVI~1\avupdsvc.exe
    C:\WINNT\System32\CTsvcCDA.EXE
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\slserv.exe
    C:\WINNT\wanmpsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\atiptaxx.exe
    C:\WINNT\soundman.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINNT\mHotkey.exe
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    C:\Program Files\Logitech\ImageStudio\LogiTray.exe
    C:\ANTIVI~1\AvMaiSrv.exe
    C:\Program Files\Creative\PlayCenter2\CTNMRUN.EXE
    C:\Program Files\[email protected]\[email protected]
    C:\Program Files\Creative\ShareDLL\MediaDet.Exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\America Online 8.0\aoltray.exe
    c:\ANTIVI~1\avServer.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\MSOffice\Office\FINDFAST.EXE
    C:\MSOffice\Office\MSOFFICE.EXE
    C:\Program Files\TechSmith\SnagIt 6\SnagIt32.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINNT\System32\explorer.exe
    C:\Startup List\StartupList.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\xxx\Start Menu\Programs\Startup]
    Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
    Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
    Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup]
    America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
    Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINNT\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    Synchronization Manager = mobsync.exe /logon
    ATIModeChange = Ati2mdxx.exe
    AtiPTA = atiptaxx.exe
    SoundMan = soundman.exe
    SynTPLpr = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    CHotkey = mHotkey.exe
    NeroCheck = C:\WINNT\system32\NeroCheck.exe
    NewsUpd = C:\Program Files\Creative\News\NewsUpd.EXE /q
    Register MediaRing Talk = C:\Program Files\MediaRing Talk\register.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    NOMAD Detector = "C:\Program Files\Creative\PlayCenter2\CTNMRUN.EXE"
    seticlient = C:\Program Files\[email protected]\[email protected] -min
    LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    WebCamRT.exe =

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

    --------------------------------------------------

    Enumerating Download Program Files:

    [Shockwave ActiveX Control]
    InProcServer32 = C:\WINNT\system32\MACROMED\Director\SwDir.dll
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab

    [{3717DF57-0396-463D-98B7-647C7DC6898A}]
    CODEBASE = http://www.searchit.com/toolbar/srchitbar.cab

    [Update Class]
    InProcServer32 = C:\WINNT\System32\iuctl.dll
    CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37602.9377430556

    [Shockwave Flash Object]
    InProcServer32 = C:\WINNT\System32\macromed\flash\Flash.ocx
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating Windows NT logon/logoff scripts:
    *No scripts set to run*

    Windows NT checkdisk command:
    BootExecute = autocheck autochk *

    Windows NT 'Wininit.ini':
    PendingFileRenameOperations: \??\C:\WINNT\DOWNLO~1\IEGator.dll|||O

    --------------------------------------------------
    End of report, 5,949 bytes
    Report generated in 0.200 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  4. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    You are still showing:

    C:\WINNT\System32\explorer.exe

    as a running process in addition to the normal C:\WINNT\Explorer.EXE

    Try running Panda's scan and see if it will pick it up.

    http://www.pandasoftware.com/activescan/

    You can try deleting the file manually, but you will probably have to end task the process first; I'm not sure if you can distinguish the two in your Task Manager. If you end task the wrong one you will probably have to restart.

    Just don't delete the one in the WinNT folder.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/117926

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice