1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Seem to have closed... a lot

Discussion in 'Earlier Versions of Windows' started by TheShadow395, Jan 5, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    Oh dear oh dear.

    I seem to have closed several Windows processes... by, uh, accident. I started using a program called "EndItAll 2", which, as the name implies, closes all the stupid pointless proggies which clog up your system. It has built-in and default safeguards, neither of which I have changed... and yet...

    It seems to have lodged itself somewhere or done something really horrible so now I can't execute any programs. I can't start them manually and they don't open at startup.

    (The) last time I used EndItAll, I think after a while my PC froze (it does that a lot, but that's a different story :) ) and I Ctrl/Alt/Del-ed my way out. It seems, however, that Windows has forgotten how to do such complex things as launch programs.

    Ctrl/Alt/Del list ATM

    Tech Support Guy Forums - Post New Thread - MSie
    Explorer
    Explorer [no, that's not a typo]
    mdm

    notably NOT systray, which has shown up before...

    I've tried Safe Mode - makes no difference
    Was about to try changing my shell to Progman [Win 3.1 style], but I decided to seek (expert :cool: ) help here instead.

    There's some technical (programming) info on EndItAll at:
    http://www.pcmag.com/article2/0,4149,573112,00.asp

    Any help will be very mcuh appreciated!

    Thanks,
    Alex

    PS: Using WinME
     
  2. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    Why is nobody replying :( ?
     
  3. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,907
    First Name:
    Frank
    It's only been 21 minutes between your 2 posts. Give these guys a chance to answer you. This service is free and is run by people who want to help. Don't expect an answer at the snap of your finger.

    What do you have checked and running in MSCONFIG?


    Frank's Windows 95/98 Tips:)
     
  4. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    Sorry, it's just that I need to get it working for my dad - he has loads of work to do on Tuesday and needs the PC. Thanks, and sorry again. I'll calm down now :).

    Erm, btw, I do mean I can't run anything - including MSCONFIG...
    oh...
    take that back...

    I think I can run 16-bit programs in DOS - I can open EDIT in a DOS prompt, anyway.
     
  5. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    I can change my shell to the program I want, though... Startup list coming soon...

    Appended:
    Now!

    ==================================================
    StartupList report, 05/01/2003, 14:57:11 AM
    StartupList version: 1.50
    Started from : C:\WINDOWS\STLIST.EXE
    Detected: Windows ME (Win9x 4.90.3000)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
    C:\WINDOWS\SYSTEM\MDM.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\REGSRV.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WEBSCANX.EXE
    C:\WINDOWS\STLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    Office Startup.lnk = C:\Program Files\MSOffice\Office\OSA.EXE
    Pop-Up Stopper.lnk = C:\Program Files\Pop-Up Stopper\dpps2.exe
    Works Reminders.lnk = C:\Program Files\MSWorks\Calendar\WKCALREM.EXE

    Shell folders Common Startup:
    [C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
    Mouse.lnk = C:\WINDOWS\SYSTEM\mswheel.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    TaskMonitor = c:\windows\taskmon.exe
    bpcpost.exe = c:\windows\SYSTEM\bpcpost.exe
    SystemTray = SysTray.Exe
    3dfx Tools = rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
    Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    McAfeeWebScanX = C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.exe
    Canary = C:\WINDOWS\Canary.exe
    sp = regedit -s C:\WINDOWS\sp.reg
    1stImpression = C:\PROGRAM FILES\1STIMPRESSION-2.5.0\1ST.EXE /CHANGE
    wcmdmgr = C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
    QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
    MessengerPlus = "C:\Program Files\Messenger Plus! Extension\MsgPlus.exe"
    System Profile = c:\windows\system\regsrv.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    LicCtrl = rundll32.exe C:\WINDOWS\MMFS.DLL,Service
    State Manager = C:\WINDOWS\System\Restore\StateMgr.exe
    Load PowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    winmodem = WINMODEM.101\wmexe.exe
    Cleanup = C:\PROGRAM FILES\COMPLETE CLEANUP TRIAL\compind.bat
    Machine Debug Manager = C:\WINDOWS\SYSTEM\MDM.EXE
    Wallpaper Switch = C:\wpchange.bat
    McAfeeVirusScanService = c:\Program Files\Network Associates\McAfee VirusScan\Avsynmgr.exe
    *StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    System Profile = c:\windows\system\regsrv.exe
    Lightbulb Joke = C:\Maestro\LbJoke\Maestro.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    MSMSGS = "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
    SOS = C:\PROGRAM FILES\STEGANOS ONLINE SHIELD\SOS.EXE /s

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [Disabled]
    CloneCDTray = "C:\Program Files\Elaborate Bytes\CloneCD v4\CloneCDTray.exe"
    EZStart = C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\EzStart.exe
    wcmdmgr = C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
    LoadQM = loadqm.exe
    ddeproc = C:\Program Files\Acceleration Software\Webcelerator\ddeproc.exe
    LSPfix = C:\Program Files\Common Files\eAcceleration\LSPfix\LSPmonitor.exe normal
    Go!Zilla dial-up fix = "C:\PROGRAM FILES\GOZILLA\GO.EXE" /FIXRAS
    QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
    PCHealth = c:\windows\PCHealth\Support\PCHSchd.exe -s
    Simu =

    [OptionalComponents]
    *No values found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    [Disabled]
    McAfee Virus Scan = C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    Scheduling Agent = mstask.exe
    McAfee TaskMaster = "C:\Program Files\McAfee\McAfee Shared Components\Crash Protector\TASKMSTR.EXE" /taskman:1

    --------------------------------------------------

    File association entry for .EXE:
    HKEY_CLASSES_ROOT\exefile\shell\open\command

    (Default) = winampw.exe "%1" %*

    --------------------------------------------------

    Enumerating Active Setup stub paths:
    HKLM\Software\Microsoft\Active Setup\Installed Components
    (* = disabled by HKCU twin)

    [{89820200-ECBD-11cf-8B85-00AA005B4395}] *
    StubPath = regsvr32.exe /s /n /i:U shell32.dll

    [>PerUser_MSN_Clean] *
    StubPath = c:\windows\msnmgsr1.exe

    [PerUser_LinkBar_URLs] *
    StubPath = c:\windows\COMMAND\sulfnbk.exe /L

    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
    StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}

    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
    StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}

    [>IEPerUser] *
    StubPath = RUNDLL32.EXE IEDKCS32.DLL,BrandIE4 SIGNUP

    [{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
    StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
    StubPath = C:\WINDOWS\SYSTEM\ie4uinit.exe

    --------------------------------------------------

    Load/Run keys from C:\WINDOWS\WIN.INI:

    load=
    run=c:\fvault.exe

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=stlist.exe
    SCRNSAVE.EXE=C:\WINDOWS\SYSTEM\CURVES~1.SCR
    drivers=mmsystem.dll power.drv

    --------------------------------------------------

    Checking for EXPLORER.EXE instances:

    C:\WINDOWS\Explorer.exe: PRESENT!

    C:\Explorer.exe: not present
    C:\WINDOWS\Explorer\Explorer.exe: not present
    C:\WINDOWS\System\Explorer.exe: not present
    C:\WINDOWS\System32\Explorer.exe: not present
    C:\WINDOWS\Command\Explorer.exe: not present

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 31/12/2002, 16:37:2)

    [rename]
    nul=c:\windows\TEMP\~f1d055.tmp

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    SET COMSPEC=C:\WINDOWS\COMMAND.COM
    SET windir=C:\WINDOWS
    SET winbootdir=C:\WINDOWS
    SET PROMPT=Windows ME $p$g
    SET TEMP=C:\windows\TEMP
    SET TMP=c:\windows\TEMP
    SET BLASTER=A220 I5 D1 H5 P330 T6
    SET CTSYN=C:\WINDOWS
    C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
    SET PATH=c:\windows;c:\windows\COMMAND;C:\PROGRA~1\MSOFFICE\OFFICE;C:\PROGRA~1\WIN98RK;c:\PROGRA~1\NETWOR~1\PGP65
    SET DIRCMD= /P /O:GNE
    SET CLASSPATH="C:\Program Files\Java\j2re1.4.0\QTJava.zip"
    SET QTJAVA="C:\Program Files\Java\j2re1.4.0\QTJava.zip"

    --------------------------------------------------

    C:\WINDOWS\WINSTART.BAT listing:

    @C:\WINDOWS\tmpcpyis.bat

    --------------------------------------------------

    C:\WINDOWS\DOSSTART.BAT listing:

    C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
    @echo off
    REM
    REM
    LH C:\PROGRA~1\MSHARD~1\MOUSE\MOUSE.EXE

    --------------------------------------------------

    Checking for superhidden extensions:

    .lnk: HIDDEN! (arrow overlay: NO!)
    .pif: HIDDEN! (arrow overlay: NO!)
    .exe: not hidden
    .com: not hidden
    .bat: not hidden
    .hta: not hidden
    .scr: not hidden
    .shs: HIDDEN!
    .shb: HIDDEN!
    .vbs: not hidden
    .vbe: not hidden
    .wsh: not hidden
    .scf: HIDDEN! (arrow overlay: NO!)
    .url: HIDDEN! (arrow overlay: yes)
    .js: not hidden
    .jse: not hidden

    --------------------------------------------------

    Enumerating Browser Helper Objects:

    (no name) - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDIEHLP.DLL - {206E52E0-D52E-11D4-AD54-0000E86C26F6}
    (no name) - C:\PROGRAM FILES\WAVETOP\BIN\WAVEIE.DLL - {EA7F9A52-0A05-11D2-98C5-00104B7229C2}
    (no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    (no name) - C:\PROGRAM FILES\DAP\DAPIEBAR.DLL - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE}
    (no name) - C:\PROGRAM FILES\WEBHANCER\PROGRAMS\WHIEHLPR.DLL - {c900b400-cdfe-11d3-976a-00e02913a9e0}
    (no name) - C:\WINDOWS\DOWNLO~1\STUMBL~1.DLL - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616}
    (no name) - C:\WINDOWS\SYSTEM\COMET.DLL - {1678F7E1-C422-11D0-AD7D-00400515CAAA}
    CSBrBHO - C:\PROGRAM FILES\COMET\INSTALL\TEMP\BRBHO12A.DLL - {96DA5BEE-4ACC-476C-B3EC-54C6730C4293}
    (no name) - c:\windows\system\googletoolbar_en_1.1.66-deleon.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    PCHealth Scheduler for Data Collection.job
    Refill the Printer.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [CV3 Class]
    InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
    CODEBASE = http://windowsupdate.microsoft.com/R824/V31Controls/x86/mil/en/actsetup.cab

    [HeartbeatCtl Class]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\HRTBEAT.OCX
    CODEBASE = http://fdl.msn.com/zone/Z4/heartbeat.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [Zoom Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ZACTIVEX.DLL
    CODEBASE = http://www.zoomify.com/download/zoomify204.cab

    [QuickTime Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
    CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

    [{8522F9B3-38C5-4AA4-AE40-7401F1BBC851}]
    CODEBASE = http://66.28.45.60/Download_Plugin.exe

    [iCC Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PCPCONNCHECK.DLL
    CODEBASE = http://www.pcpitstop.com/internet/pcpConnCheck.cab

    [IntraLaunch.MainControl]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INTRALAUNCH.OCX
    CODEBASE = file://D:\SuperCD\IntraLaunch.CAB

    [{95844941-7934-4693-92D9-8202EA7B20ED}]
    CODEBASE = http://www.stumbleupon.com/stumble.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    Protocol #1: C:\WINDOWS\webhdll.dll
    Protocol #2: C:\WINDOWS\webhdll.dll
    Protocol #3: C:\WINDOWS\webhdll.dll
    Protocol #4: C:\WINDOWS\webhdll.dll
    Protocol #11: C:\WINDOWS\webhdll.dll

    --------------------------------------------------
    End of report, 11,354 bytes
    Report generated in 2.523 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  6. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    Also, I have a shortcut to shutdown, which involves RUNDLL32, but this no longer works, saying it cannot be run without "wtndll.exe". Does this mean anything to anyone?
     
  7. Hairy

    Hairy

    Joined:
    Mar 20, 2000
    Messages:
    574
  8. Hairy

    Hairy

    Joined:
    Mar 20, 2000
    Messages:
    574
    are you sure that doesn't say windll.exe instead of w<B>T</B>ndll.exe
    that would be more virus, if it is....

    and this too:
    Lightbulb Joke = C:\Maestro\LbJoke\Maestro.exe

    just the ones i saw that stuck out....
     
  9. TheShadow395

    TheShadow395 Thread Starter

    Joined:
    Jan 5, 2003
    Messages:
    92
    Thanks, but I'm afraid that CANARY.EXE is some logging thing I installed some time ago so that (bright idea, eh? :) ) I could look at what I'd done before stuff went wrong. And LbJoke is a custom thing I put on at startup to show a lightbulb joke ( :D ) at startup and forgot to remove.

    I'll run a virus scan today though, I'll keep you posted.

    One thing I noticed, though, was that although StartList showed all the processes I am familiar with, neither C/A/Del nor my system tray showed any of these, with the exceptions of wmexe and mdm on C/A/D and my virus scanner in the tray.

    Another thing - a few programs do seem to open - WinZip opens after a download (namely StartList) and images open in IrfanView, a freeware image viewer I have.

    [Appended]:
    In fact, it seems that files will open in the program they have associations with, so if need be I can create associations for all programs I run and empty files with names like ' ' and maybe be able to open stuff like virus scanners w/o having to edit my shell!

    Thanks for your time,
    Alex
     
  10. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/111499

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice