Msconfig

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
User avatar
WolfgangPC
Regular Member
Posts: 221
Joined: Sun Oct 06, 2002 1:18 pm
Location: Canada

Msconfig

Post by WolfgangPC »

Hey all, question, when I go to open msconfig from the run command, after I hit OK the msconfig screen will only stay open for mabye 3 seconds if that?? Anyone got any ideas?It has never done this before..l :confused:
...If Wile E. Coyote had enough money to buy all that ACME crap,why didn't he just buy dinner???..
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

Update your virus scanner and scan for viruses.
User avatar
Norm
SG VIP
Posts: 14195
Joined: Tue Mar 27, 2001 12:00 pm

Post by Norm »

CableDude wrote:Update your virus scanner and scan for viruses.
Seconded.
User avatar
WolfgangPC
Regular Member
Posts: 221
Joined: Sun Oct 06, 2002 1:18 pm
Location: Canada

Post by WolfgangPC »

OK, I have done total and complete scans with both AVG Pro and Norton 2004 Pro, and they both have found nothing, there is a WUXAT.EXE that keps showing up in Startup and when I go into Task Manager, when I end procces in Task Manager the msconfig screen opens and stays open just fine, then I reboot and I am back to square one, and ideas of what this is, and how to get rid of it for good?
...If Wile E. Coyote had enough money to buy all that ACME crap,why didn't he just buy dinner???..
User avatar
Norm
SG VIP
Posts: 14195
Joined: Tue Mar 27, 2001 12:00 pm

Post by Norm »

Took a while, the net is slow and had to translate a couple of pages.
Only thing I found points to it being Worm.P2P.SpyBot.gen


Found Here

Worm.P2P.SpyBot.gen and what Symantec Security Response has to say about it.





Hello,
the file C:\WINDOWS\System32 \ WUXAT.EXE , which is started here:
O4 - HKLM\..\Run: [ Configuration default ] WUXAT.EXE
the only case of Trojan inheritance seems to be. One must itself however in the clear one over it
its that each infestation is not to be recognized by a HJT log file. The others
Entries are OK ONE, but theoretically these files could overwritten
its, particularly it itself with Worm.P2P.SpyBot.gen around a Backdoor Trojaner
acts, i.e. if it is active, it opens a "back door" on your system,
announces themselves at IRC servers and expects instructions. It is also able
To store and dispatch if necessary keyboard layouts. Whether he did that, I know
not, you know not, white nobody. For me it became personal as cause for a formatting and a new installation is enough, because it me simply too riskily
it would be that he was nevertheless active or is.
On the other side the process typical for this Trojaner is missing with you
SVC host s (with s). Whether that is a rather good or bad indication, can
I do not say.
The decision is with you.
If you should decide nevertheless for a repair attempt, you find
hier eine
genaue Beschreibung und Möglichkeiten der manuellen Bereinigung der registry
und der zu löschenden Dateien - aber sicher sein kannst Du danach nicht mehr,
daß niemand "mithört"...
Gruß,
ixus
Post Reply