Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
when i go to Start/Run and type 'msconfig' or 'regedit' they will open for a split second then automatically close out before i can do anything. I booted my comp in safe mode and they open up fine but did not see any odd programs running at startup. I don't think it's a virus but could be. I ran scandisk and norton anti virus but they found nothing. Any help? Please...

don't have a sure answer here but since it works in safe mode it could be your graphics or theme?, seen this happen on a friends computer only cause he uses all these theme custom desktop things and some programs dont like it.
look at your event log viewer after trying to start them, if you see a drwatson or application error it might help you.

Your .exe file association has been altered by a virus. Go here and download and run the Exe file association fix.
http://www.dougknox.com
In the left hand pane click 'WinXP fixes', then in the main window click 'File Association fixes'. Download the Exe file association fix and double click on it.Then run an online virus scan here and post the results.

More help here if needed .
http://www.kellys-korner-xp.com/regs_edits/restoreregistry.reg
173. Repair the Registry Editorhttp://www.kellys-korner-xp.com/regs_edits/msconfigregtm.reg
Restore Msconfig, Regedit and Task Manager

Scan started at 8/4/2003 9:30:03 AM
Scanning memory...
Scanning boot sectors...
Scanning files...
F:\WINDOWS\system32\H@tKeysH@@k.DLL - Keylogger/Win32.HatKeys -> Infected
F:\WINDOWS\system32\lolx.exe->(FSGPE) - Backdoor:IRC/SdBot -> Infected
F:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0BBQ735T\xdcc[1].exe - Win32/HLLW.Autorooter -> Infected
F:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\9B0C0VXX\xdcc[1].exe - Win32/HLLW.Autorooter -> InfectedScanned
============================
Objects: 107214
Directories: 6640
Archives: 2431
Size(Kb): -1810047
Infected files: 4Found
============================
Viruses found: 3
Suspicious files: 0
Disinfected files: 0
Mail files: 107Here is the report after scanning

Is it only msconfig that will not open? Or is it no .exe will open?
If it's only msconfig that won't open, Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, click "Save Log", and copy and paste it in a reply. Also open HT again and click 'Config' and 'Misc Tools'.
Then click 'Generate startuplist log'.
Copy and paste that log in your reply as well.

it is msconfig, sysedit, ctrl+alt+del, regedit, those are just a few that i tried and they close out as soon as they open.

Here is the log:
Logfile of HijackThis v1.96.0
Scan saved at 1:16:45 PM, on 8/5/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\Explorer.exe
F:\Program Files\Norton Personal Firewall\NISUM.exe
F:\Program Files\Norton Personal Firewall\ccPxySvc.exe
F:\WINDOWS\System32\CTsvcCDA.exe
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\wanmpsvc.exe
F:\WINDOWS\System32\MsPMSPSv.exe
F:\Program Files\Creative\ShareDLL\CtNotify.exe
F:\Cyberpwr\PanPlus.exe
F:\Program Files\BroadJump\Client Foundation\CFD.exe
F:\WINDOWS\System32\devldr32.exe
F:\PROGRA~1\NORTON~1\navapw32.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\Creative\ShareDLL\MediaDet.exe
F:\WINDOWS\System32\MSCONFIG32.exe
F:\WINDOWS\System32\ctfmon.exe
F:\PROGRA~1\AWS\WEATHE~1\Weather.exe
F:\WINDOWS\NCLAUNCH.exe
F:\WINDOWS\System32\P2P Networking\P2P Networking.exe
F:\Program Files\AIM95\aim.exe
F:\Program Files\Internet Explorer\IEXPLORE.exe
F:\PROGRA~1\WINZIP\winzip32.exe
F:\Documents and Settings\Brian195\Local Settings\Temp\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = F:\WINDOWS\System32\blank.htm
O1 - Hosts: 65.120.116.173 lite.aimster.com
O2 - BHO: (no name) - {9FD12933-810D-4526-B7C4-0914E098D384} - F:\Program Files\Kontiki\bin\BH205171.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Disc Detector] F:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [Power Panel plus] F:\Cyberpwr\PanPlus.exe
O4 - HKLM\..\Run: [BJCFD] F:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NAV Agent] F:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "F:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SSRunScript] "F:\Program Files\Support.com\Charter\bin\SSRunScript.exe" /script "F:\Program Files\Support.com\Charter\vbs\verifyconnection.vbs" /args //b startupdelay
O4 - HKLM\..\Run: [MSConfig] MSCONFIG32.exe
O4 - HKLM\..\Run: [P2P Networking] F:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\RunServices: [system] dcomx.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] F:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [NCLaunch] F:\WINDOWS\NCLAUNCH.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://F:\Program Files\Kontiki\bin\BH205171.dll/201
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D2DCA0D-B30F-40AD-9690-087105F214EC} (IEDial Class) - http://usa-download.nocreditcard.com/download/Object/ieaccess2XP.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25b64428e572e36cdc05/netzip/RdxIE601.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP Professional Step by Step Interactive) - file://F:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://208.158.118.13/AxisCamControl.ocx
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37652.8384606481
O16 - DPF: {A7798D6C-C6B5-4F26-9363-F7CDBBFFA607} (download Class) - http://www.gigex.com/ActiveX/vxpspeeddelivery.dll
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D32C3BAD-5213-49BD-A7D5-E6DE6C0D8249} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.6.9.9/tukati.cab
Here is the startuplist:StartupList report, 8/5/2003, 1:17:34 PM
StartupList version: 1.52
Started from : F:\Documents and Settings\Brian195\Local Settings\Temp\HijackThis.exe
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2600.0000)
* Using default options
==================================================Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\Explorer.exe
F:\Program Files\Norton Personal Firewall\NISUM.exe
F:\Program Files\Norton Personal Firewall\ccPxySvc.exe
F:\WINDOWS\System32\CTsvcCDA.exe
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\wanmpsvc.exe
F:\WINDOWS\System32\MsPMSPSv.exe
F:\Program Files\Creative\ShareDLL\CtNotify.exe
F:\Cyberpwr\PanPlus.exe
F:\Program Files\BroadJump\Client Foundation\CFD.exe
F:\WINDOWS\System32\devldr32.exe
F:\PROGRA~1\NORTON~1\navapw32.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\Creative\ShareDLL\MediaDet.exe
F:\WINDOWS\System32\MSCONFIG32.exe
F:\WINDOWS\System32\ctfmon.exe
F:\PROGRA~1\AWS\WEATHE~1\Weather.exe
F:\WINDOWS\NCLAUNCH.exe
F:\WINDOWS\System32\P2P Networking\P2P Networking.exe
F:\Program Files\AIM95\aim.exe
F:\Program Files\Internet Explorer\IEXPLORE.exe
F:\PROGRA~1\WINZIP\winzip32.exe
F:\WINDOWS\system32\NOTEPAD.exe
F:\Documents and Settings\Brian195\Local Settings\Temp\HijackThis.exe---------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = F:\WINDOWS\system32\userinit.exe,---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicessystem = dcomx.exe
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Runctfmon.exe = F:\WINDOWS\System32\ctfmon.exe
Weather = F:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
NCLaunch = F:\WINDOWS\NCLAUNCH.exe---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceMSConfig = MSCONFIG32.exe
---------------------
Shell & screensaver key from F:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*---------------------
Enumerating Browser Helper Objects:(no name) - F:\Program Files\Kontiki\bin\BH205171.dll - {9FD12933-810D-4526-B7C4-0914E098D384}
NAV Helper - F:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}---------------------
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Symantec NetDetect.job---------------------
Enumerating Download Program Files:
[QuickTime Object]
InProcServer32 = F:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab[Shockwave ActiveX Control]
InProcServer32 = F:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[IEDial Class]
InProcServer32 = F:\WINDOWS\System32\IEAccess2.dll
CODEBASE = http://usa-download.nocreditcard.com/download/Object/ieaccess2XP.cab[RdxIE Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\RdxIE.dll
CODEBASE = http://207.188.7.150/25b64428e572e36cdc05/netzip/RdxIE601.cab[ExentInf Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\exentctl_0_0_0_1.ocx
CODEBASE = http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx[GigexCtrl ActiveX]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\gigexagent.dll
CODEBASE = http://www.gigex.com/tv/igor/gigexagent.dll[Microsoft Office XP Professional Step by Step Interactive]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\mitm0026.dll
CODEBASE = file://F:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab[GSDACtl Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\gsda.dll
CODEBASE = http://launch.gamespyarcade.com/software/launch/alaunch.cab[InstallShield International Setup Player]
InProcServer32 = f:\windows\downlo~1\isetup.dll
CODEBASE = http://www.installengine.com/engine/isetup.cab[CamImage Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\AxisCamControl.ocx
CODEBASE = http://208.158.118.13/AxisCamControl.ocx[Update Class]
InProcServer32 = F:\WINDOWS\System32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37652.8384606481[download Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\vxpspeeddelivery.dll
CODEBASE = http://www.gigex.com/ActiveX/vxpspeeddelivery.dll[Live365Player Class]
InProcServer32 = F:\WINDOWS\DOWNLO~1\Play365.dll
CODEBASE = http://www.live365.com/players/play365.cab[Shockwave Flash Object]
InProcServer32 = F:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[CRAVOnline Object]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\ravonline.dll
CODEBASE = http://www.ravantivirus.com/scan/ravonline.cab[Tukati Launcher]
InProcServer32 = F:\WINDOWS\System32\TukatiClientInstaller.dll
CODEBASE = http://3dgamers.tukati.com/tukati/1.6.9.9/tukati.cab---------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: F:\WINDOWS\system32\SHELL32.dll
CDBurn: F:\WINDOWS\system32\SHELL32.dll
WebCheck: F:\WINDOWS\System32\webcheck.dll
SysTray: F:\WINDOWS\System32\stobject.dll---------------------
End of report, 7,159 bytes
Report generated in 0.031 secondsCommand line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Your right! Do the following:
1. Click Start > Run > type command and click OK. A command prompt will open.
2. Type in cd \winnt and hit enter.
3. Type in copy regedit.exe regedit.com and hit enter.
4. Type in start regedit.com and hit enter.Then Click the + next to the following keys
HKEY_CURRENT_USER
Software
Microsoft
Windows
CurrentVersionScroll down and right click on the RunOnce folder and click delete.
Scroll up and click the - next to HKEY_CURRENT_USER.Click the + next to the following keys
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersionScroll down and click on the Run folder. In the right hand window right click on the following and click delete.
MSCONFIG32.EXEScroll down and click on the RunServices folder. In the right hand window right click on the following and click delete.
system = dcomx.exeClose regedit and reboot.
Delete:
dcomx.exe
MSCONFIG32.EXE
And any remaining files in the Rav report.Run the .exe file association fix.

Ooppss, Gave some wrong info above. When you open the command prompt, type the following and hit enter after each.
cd\
cd \windows
copy regedit.exe regedit.com

i did all that and rebooted and it still doesn't open up right. Although i did a search in the regedit for all instances of 'msconfig32' and 'dcomx' and it found them in some other places. Is it safe to delete all of them that it finds?

Yeah, remove all the registry entries..
Whatever this virus is, it is new. No one has a write up.
Also, go here and run a scan on Msconfig32.exe.
http://www.kaspersky.com/remoteviruschk.html

my antivirus detected it and here is some info
http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html
i am going to do all the stuff that you said to do plus these things

the good thing is now i can run 'sysedit' and 'regedit' through Start/Run but i still can't use ctrl+alt+del or msconfig...When i delete the value in regedit it pops back up. I can't delete the file "msconfig32.exe" through windows explorer since 'access is denied'

THE VIRUS IS GONE!!! i ended up using all those methods in safe mode and making sure my comp wasn't on 'system restore' and i deleted the file 'msconfig32.exe' which was the corrupted file. Thank you for your help Tom! you are the best. It's good to see that there are nice people out there willing to share their knowledge with others.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |