[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

C:\WINNT\SYSTEM32\AUTOEXEC.NT. The system files is not suitable for running MS-DOS and Microsoft Windows applications.

Posted on 2004-12-01
10
Medium Priority
?
552 Views
Last Modified: 2010-04-14
When running a MS-DOS or 16-bit windows-based program I get the follwoing error -
C:\WINNT\SYSTEM32\AUTOEXEC.NT. The system files is not suitable for running MS-DOS and Microsoft Windows applications.
I have researched it with microsoft and I have now expanded from the Windows 2000 CD the autoexec.nt, command.com, and the config.nt.   Actually have done this multiple times, and it has not helped a bit.
Any help would be greatly appreciated.  Thanks in advance.
0
Comment
Question by:sissyl
  • 6
  • 4
10 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12717345
Hello sissyl =)

Open your C:\Windows\Repair folder, and try to copy two files from there, Config.NT and Autoexec.NT
Then open C:\Windows\System32 folder, move the Config.NT and Autoexec.NT files from here to recycle Bin and paste the files you copied from the Repair folder !!
Restart and now check ??

You can also try to copy these files form another WinXP system which is working fine.... :)
Coz the error u are getting is caused by the corruption of either of these two files, and replacing them with good copies can solve the problem :)

Or u can also manually edit these files,,,, follow the instructions here :)
Error message when you install or start an MS-DOS or 16-bit Windows-based program
http://support.microsoft.com/default.aspx?scid=kb;en-us;324767
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12717372
**replace Windows with WINNT in the above suggestion**

Also sometimes what happens that if the system is infected with some virus, most likely with Worm.Agobot then it delete the Autoexec.NT file on each restart..... so are you sure that nothing like this is happening in your system ??
0
 

Author Comment

by:sissyl
ID: 12720649
I have done all of this and it doesn't help.  What I did look into was the Worm.Agobot.  I have something on my machine but McAffee isn't picking it up, even after updating the virus pattern.  I wasn't unable to find any removal tools and was hoping that you could send me in the right direction faster than the circles I am going around.
Thanks again
0
Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12720677
You can try running Stinger in safemode >> http://vil.nai.com/vil/stinger
or take this online virus scan >> http://housecall.trendmicro.com/

if they dont pick anything the try to Download HijackThis v1.98.2 from here, run it and Save the LOG file:
http://tools.radiosplace.com/HijackThis.exe

Then Post that log at this site >> http://www.hijackthis.de/index.php?langselect=english
hit analyse, scroll down, hit Save Analyse, a new page will open, paste here the address of that page,,,, i will have a loook on the system that what's going wrong :)
0
 

Author Comment

by:sissyl
ID: 12721299
I ran stinger and it didn't appear to catch anything.  I ran HijackThis and this is the list that it pulled.

Logfile of HijackThis v1.98.1
Scan saved at 2:37:35 PM, on 12/1/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\myCIO\VScan\McShield.exe
C:\WINNT\myCIO\Agent\myAgtSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\myCIO\Agent\swAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\myCIO\Agent\myagttry.exe
C:\WINNT\system32\rfjueb.exe
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
C:\Program Files\Windows AdControl\WinAdCtl.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Sony Handheld\USBSwt.exe
C:\Program Files\Windows AdControl\WinAdAlt.exe
C:\WINNT\TIREMOTE\wuser32.exe
C:\WINNT\TIREMOTE\TIRemote.exe
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker1.exe
C:\Documents and Settings\sissyl\Desktop\is\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.circuitassembly.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINNT\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINNT\myCIO\VScan\Splash.exe
O4 - HKLM\..\Run: [bkgcpktbp] C:\WINNT\system32\rfjueb.exe
O4 - HKLM\..\Run: [conscorr] C:\WINNT\conscorr.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINNT\wupdt.exe
O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe
O4 - Startup: timngr.bat
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Sony PDA USB Switcher.lnk = C:\Program Files\Sony Handheld\USBSwt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=2ddf89e45f6cc571f238df4bb03e9573ec1fc7e208fca2ebb7993a58217923ffe9bfc2f8a68045679d1c2e4421401bac2e6f16ed20376ecb8619b7315e:37a13eb4f412092027c6055a05c2747c
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/SonicWall/bin/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A59F8D2E-0B44-4352-A39A-83BDAA67F2DB}: NameServer = 192.168.1.4
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINNT\myCIO\Agent\myRmProt2.8.1.107.dll

0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 2000 total points
ID: 12721470
hmmmmmm bad stuff =\
try this, First get these tools and install Adaware and Spybot and update them to the latest definations,

AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml

Then run hijackthis, check the following lines and click on fix checked!!

=========================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [bkgcpktbp] C:\WINNT\system32\rfjueb.exe
O4 - HKLM\..\Run: [conscorr] C:\WINNT\conscorr.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINNT\wupdt.exe
O4 - Startup: timngr.bat
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=2ddf89e45f6cc571f238df4bb03e9573ec1fc7e208fca2ebb7993a58217923ffe9bfc2f8a68045679d1c2e4421401bac2e6f16ed20376ecb8619b7315e:37a13eb4f412092027c6055a05c2747c
==============================================

Then boot the system in Safemode and Run all of them one by one and delete everything they detect.
delete these files from C:\WINNT if they are present >> rfjueb.exe, conscorr.exe, wupdt.exe
Search your hard drive for timngr.bat and delete it (i dont know if you are running it yourself but its a batch file and batch files are known for creating "wrong" things)
Then delete the temporary internet files and history of IE and run Disk Cleanup on your hard drive to delete those temp and junk files.
Restart back in Normal Mode to check for the problems now ?? :)
1
 

Author Comment

by:sissyl
ID: 12721532
I have this software already, have been running it avidly the last few days trying to figure this out.  But I will run all again and take those you mention from HijackThis.  The timngr.bat is a file that I have setup, all it is doing is running a monitor service on my network for each pc.    I will run all this and get right back to you.  
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12721558
yeah i knew that you wre running all those tools..... and its a sad thing that they will leaving all those junks on your system still.... plzz dont forget to run CWShredder2.0 and deleting those offending files manually if they are present on the system..... otherwise they will reinfect the system at some time in future.... and sorry about that batch file..... had no idea about that :)
0
 

Author Comment

by:sissyl
ID: 12729012
Thank you very very very much.  It is finally all clean and running great.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12729051
Excellent..... ^_^
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article will help to fix the below errors for MS Exchange Server 2016 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question