MSconfig not running

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by adrianlee, Nov 17, 2006.

  1. adrianlee

    adrianlee Private E-2

    Hi

    Hopefully someone can help. Stuck in safe mode and msconfig not opening to allow me back into normal mode. Here's my Hijackthis log


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    Any help would be grateful
     
    Last edited by a moderator: Nov 17, 2006
  2. adrianlee

    adrianlee Private E-2

    Running XP
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    PAY CLOSE ATTENTION to step 3 in the below sticky since you are seriously violating this step.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. adrianlee

    adrianlee Private E-2

    More info

    Preliminary House Cleaning and setup - unable to open add/remove programs.
    Msconfig - unable to open msconfig

    when trying to run these task manager opens 'drwtsn' many times and closes application.

    Unable to get back into normal mode to complete any other tasks (at work using pc to do this)

    downloaded hijackthis and ran to try to get some info to help
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can do the below!

    Run this WareOut Removal and attach the requested log.


    Then from the READ & RUN ME, jsut get me logs from
    - GetRunKey
    - ShowNew
    - HijackThis
     
  6. adrianlee

    adrianlee Private E-2

    Tried to run Fixwareout but kept having NTVDM.EXE has encountered a problem. I have attached the log but looks empty. Ran newfiles log same error also had Attribute Utility has encountered a problem, log also looks empty. Runkeys log attached. Also attached the hijack file on next post
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give me the exact word for word NTVDM.EXE error message.

    You are not following the directions for using GetRunKey and ShowNew. You must extract ALL files from the ZIPs and you must run the .bat files from a Windows Explorer session. It you run them from inside the ZIP (like you are doing), they will not work.
     
  8. adrianlee

    adrianlee Private E-2

    This is the error word for word

    NTVDM.EXE

    NTVDM.EXE has encountered a problem and needs to close. we are sorry for the inconvenience.
    if you were in the middle of something, the information you were working on might be lost.

    Error signature

    AppName: ntvdm.exe
    ModVer: 5.1.2160.2180

    AppVer : 5.1.2160.2180
    Offset : 0005fe0e

    ModName: ntvdm.exe

    Also attached the technical info

    Ran getrunkeys and showfiles again unzipped and through explorer same results

    When trying to run msconfig similar error occurs have also attached the tech info
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may be better off approaching this NTVDM problem in the Software Forum. Or you could take a look at the below from Microsoft and see if you can follow it and if it helps.

    http://support.microsoft.com/kb/165214/en-us


    What did you attach with technical info? Were those XML files? Why did you attach that?
     
  10. adrianlee

    adrianlee Private E-2

    Thanks for all your support in resolving my problems

    Regards AL
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but let's see if we can do anything about some of your malware issues too. I'm not sure if your problems will block the below fixes or not. Give it a try and let me know what happens.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot into safe mode and delete the below file:
    C:\WINDOWS\system32\desktop.exe
    Now reboot into normal mode (if possible)!

    Now attach the below new logs (even though they may not work properly) and tell me how the above steps went.

    1. GetRunKey
    2. HJT


    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds