My Task Manager disappears when I hit CTRL+ALT+DELETE

  • Thread starter Thread starter David
  • Start date Start date
D

David

Any ideas?

Every time I try to bring up my Task Manager via
CTRL+ALT+DELETE, the window appears for a fraction of a
second, then disappears. The little icon for it in the
menu bar stays a little longer, but not much. The Task
Manager window will not stay open. What's causing this?
 
Yes, but you will have to get rid of the virus. There are some variants
that the AV Scanners are not catching. With the utilities that I listed,
including the Startup Programs Tracker, you should be able to begin
identifying programs that are not normal, or are suspicious. Since you'll
have the renamed version of MSCONFIG available, you can still modify your
system startup to start isolating the likely suspects.
 
You're welcome, and glad you got it resolved.


Doug thanx for making these programs!!! I am trying to make my way
through the same problem. I have been unable to get any help. I have
downloaded the startup programs tracker and here is what it said.

-- Registry - HKEY_LOCAL_MACHINE RunOnce --
DELDIR0.EXE
"C:\DOCUME~1\BILLAN~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program
Files\McAfee\McAfee Shared Components\Guardian\"

-- Registry - HKEY_LOCAL_MACHINE Run --
IgfxTray C:\WINDOWS\System32\igfxtray.exe
HotKeysCmds C:\WINDOWS\System32\hkcmd.exe
hpfsched C:\WINDOWS\hpfsched.exe
HPDJ Taskbar Utility
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
HPHmon03 C:\WINDOWS\System32\hphmon03.exe
Share-to-Web Namespace Daemon C:\Program Files\Hewlett-Packard\HP
Share-to-Web\hpgs2wnd.exe
CXMon "C:\Program
Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
WorksFUD C:\Program Files\Microsoft
Works\wkfud.exe
Microsoft Works Portfolio C:\Program Files\Microsoft
Works\WksSb.exe /AllUsers
Microsoft Works Update DetectiC:\Program Files\Microsoft
Works\WkDetect.exe
QuickTime Task C:\WINDOWS\System32\qttask.exe
WFXSwtch C:\WinFax\WFXSWTCH.exe
WinFaxAppPortStarter wfxsnt40.exe
AVG_CC C:\Program
Files\Grisoft\AVG6\avgcc32.exe /startup
IMJPMIG8.1 "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE"
/Spoil /RemAdvDef /Migration32
IMEKRMIG6.1 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
Winsock2 driver WINCFG.SCR
KernelFaultCheck
MPFExe F:\utils\McAfee.com\PERSON~1\MpfTray.exe
MSConfig C:\EmergencyUtils\MSConfig1.exe /auto
RealTray C:\Program
Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
ccApp "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
ccRegVfy "C:\Program Files\Common Files\Symantec
Shared\ccRegVfy.exe"

-- Registry - HKEY_CURRENT_USER RunOnce --
Winsock2 driver WINCFG.SCR

-- Registry - HKEY_CURRENT_USER Run --
ctfmon.exe C:\WINDOWS\System32\ctfmon.exe

-- Registry - HKEY_USERS\.DEFAULT Run --
No Items Found

-- Start Menu - Current User --
UD Agent.lnk

-- Start Menu - All Users --
No Items Found

-- Disabled Items --
No Items Found

-- Registry - Shell Value - HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon --
Explorer.exe

-- Running Processes --
System Idle Process
System
smss.exe \SystemRoot\System32\smss.exe
csrss.exe
winlogon.exe winlogon.exe
services.exe C:\WINDOWS\system32\services.exe
lsass.exe C:\WINDOWS\system32\lsass.exe
svchost.exe C:\WINDOWS\system32\svchost -k rpcss
svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
CCEVTMGR.EXE "C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe"
spoolsv.exe C:\WINDOWS\system32\spoolsv.exe
alg.exe
avgserv.exe C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
DKService.exe "C:\Program Files\Executive
Software\DiskeeperWorkstation\DKService.exe"
MpfService.exe F:\utils\McAfee.com\PERSON~1\MPFSERVICE.exe
NAVAPSVC.EXE "F:\Norton SystemWorks\Norton
AntiVirus\navapsvc.exe"
NPROTECT.EXE "F:\Norton SystemWorks\Norton
Utilities\NPROTECT.EXE"
NOPDB.EXE F:\NORTON~1\SPEEDD~1\nopdb.exe
svchost.exe C:\WINDOWS\System32\svchost.exe -k imgsvc
explorer.exe C:\WINDOWS\Explorer.EXE
wanmpsvc.exe "C:\WINDOWS\wanmpsvc.exe"
WFXSVC.EXE C:\WINDOWS\System32\WFXSVC.EXE
WFXMOD32.EXE /0
igfxtray.exe "C:\WINDOWS\System32\igfxtray.exe"
hkcmd.exe "C:\WINDOWS\System32\hkcmd.exe"
hpztsb04.exe
"C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe"
hphmon03.exe "C:\WINDOWS\System32\hphmon03.exe"
hpgs2wnd.exe "C:\Program Files\Hewlett-Packard\HP
Share-to-Web\hpgs2wnd.exe"
Hpi_monitor.exe "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo
Imaging\Hpi_Monitor.exe"
MpfAgent.exe F:\utils\McAfee.com\PERSON~1\MpfAgent.exe
-Embedding
qttask.exe "C:\WINDOWS\System32\qttask.exe"
WFXSWTCH.exe "C:\WinFax\WFXSWTCH.exe"
WFXSNT40.EXE "C:\WINDOWS\System32\wfxsnt40.exe"
hpgs2wnf.exe C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
-Embedding
avgcc32.exe "C:\Program Files\Grisoft\AVG6\avgcc32.exe"
/startup
wincfg.scr "C:\WINDOWS\System32\WINCFG.SCR" /S
MpfTray.exe "F:\utils\McAfee.com\PERSON~1\MpfTray.exe"
realplay.exe "C:\Program Files\Real\RealPlayer\RealPlay.exe"
SYSTEMBOOTHIDEPLAYER
CCAPP.EXE "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
ctfmon.exe "C:\WINDOWS\System32\ctfmon.exe"
UD.EXE "C:\Program Files\United Devices\UD.EXE"
sndvol32.exe "C:\WINDOWS\system32\sndvol32.exe"
aim.exe "C:\Program Files\AIM95\aim.exe"
ud_1706422.exe ud_1706422.exe
ud_ligfit_Release.ex"C:/Program Files/United
Devices/ud_1706422_0.dir/ud_ligfit_Release.exe" ligfit_UDrun_input
energy_dock UDX6740BBXscrSD UD
agent.exe "C:\Program Files\Agent\agent.exe"
iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe"
-nohome
MDM.EXE C:\WINDOWS\System32\mdm.exe -Embedding
fd.exe "C:\Program
Files\FreshDevices\FreshDownload\fd.exe" /ie
"http://www.dougknox.com/xp/utils/xp_emergencyutil.zip"
WINZIP32.EXE C:\PROGRA~1\WINZIP\winzip32.exe
"F:\arcs\dl\xp_emergencyutil.zip"
xp_emergencyutil.exe"F:\arcs\test\xp_emergencyutil.exe"
WINZIP32.EXE C:\PROGRA~1\WINZIP\winzip32.exe
"F:\arcs\dl\StartupTracker3.zip"
StartupTracker3.exe "F:\arcs\test\StartupTracker3.exe"
wmiprvse.exe



Can anyone lend me a hand and telling me what is
wrong?????????????????????????


Thanx for all the help in advance!
 
I see definite and probable signs of a virus infection.

First, use the "copy" of Task Manager, and go to the Processes tab.
Highlight each of the following and click End Process.

WINCFG.SCR
DELDIR0.EXE (if its running)

Then run the copy of REGEDIT and go to:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersionRun
Locate the value Winsock2 Driver in the right pane. Right click it and
select Delete.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersionRunOnce
Locate and delete the DELDIR0.EXE value in the right pane.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersionRunOnce
Locate the Winsock2 driver entry the right pane, right click it and select
Delete.

Next open Windows Explorer and go to C:\Windows\System32 and delete the
WINCFG.SCR file (this is definitely a virus).

Reboot your system and your normal Task Manager, Regedit and MSConfig should
work normally. Keep your AV software up to date, and scan your system
regularly.
 
I see definite and probable signs of a virus infection.

First, use the "copy" of Task Manager, and go to the Processes tab.
Highlight each of the following and click End Process.

WINCFG.SCR
DELDIR0.EXE (if its running)

Then run the copy of REGEDIT and go to:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersionRun
Locate the value Winsock2 Driver in the right pane. Right click it and
select Delete.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersionRunOnce
Locate and delete the DELDIR0.EXE value in the right pane.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersionRunOnce
Locate the Winsock2 driver entry the right pane, right click it and select
Delete.

Next open Windows Explorer and go to C:\Windows\System32 and delete the
WINCFG.SCR file (this is definitely a virus).

Reboot your system and your normal Task Manager, Regedit and MSConfig should
work normally. Keep your AV software up to date, and scan your system
regularly.


Doug I am gonna name my next kid after you!!!!!!!!!!!!!!!!! Works
like a champ! Now if I can figgure out why neither Norton or AVG
grabbed this booger. And both have current vir files and scan once a
day and are resident...........


Anyway thanx a lot doug I really do appreciate the help!!!!!!!
 
Hi Doug,
See if you can help me out. Please.

The sad part is c:\emergencyutils\.... contents also die on me,
The following is the output of the startup tracker.

Thanks
Annies

-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

No Items Found

-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Windows Logon Procedure SVCHOSTA.EXE
SunJavaUpdateSched C:\Program
Files\Java\jre1.5.0_01\bin\jusched.exe

-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

Windows Logon Procedure SVCHOSTA.EXE

-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

No Items Found

-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce

Windows Logon Procedure SVCHOSTA.EXE

-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run

Windows Logon Event sessmngra.exe

-- Start Menu - Current User --
No Items Found

-- Start Menu - All Users --
No Items Found

-- Disabled Items --
No Items Found

-- Registry - Shell Value - HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon --
Explorer.exe

-- Running Processes --
System Idle Process
System
smss.exe \SystemRoot\System32\smss.exe
csrss.exe
winlogon.exe winlogon.exe
services.exe C:\WINDOWS\system32\services.exe
lsass.exe C:\WINDOWS\system32\lsass.exe
svchost.exe C:\WINDOWS\system32\svchost -k rpcss
svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
spoolsv.exe C:\WINDOWS\system32\spoolsv.exe
DefWatch.exe C:\PROGRA~1\SYMANT~1\DefWatch.exe
Rtvscan.exe C:\PROGRA~1\SYMANT~1\Rtvscan.exe
nvsvc32.exe C:\WINDOWS\System32\nvsvc32.exe
explorer.exe C:\WINDOWS\Explorer.EXE
svchosta.exe "C:\WINDOWS\System32\SVCHOSTA.EXE"
wuauclt.exe "C:\WINDOWS\System32\wuauclt.exe"
firefox.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
cmd.exe "C:\WINDOWS\System32\cmd.exe"
cmd.exe "C:\WINDOWS\System32\cmd.exe"
sh.exe "C:\mks70\mksnt\sh.exe" -L
notepad.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\list
Copy_of_Regedit.com "C:\EmergencyUtils\Copy_of_Regedit.com"
StartupTracker3.exe "C:\tmp\Temporary Directory 1 for
StartupTracker3-1.zip\StartupTracker3.exe"
wmiprvse.exe

-- Running Services --

Name: AudioSrv
Description: Manages audio devices for Windows-based programs. If this
service is stopped, audio devices and effects will not function
properly. If this service is disabled, any services that explicitly
depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Browser
Description: Maintains an updated list of computers on the network and
supplies this list to computers designated as browsers. If this service
is stopped, this list will not be updated or maintained. If this
service is disabled, any services that explicitly depend on it will
fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: CryptSvc
Description: Provides three management services: Catalog Database
Service, which confirms the signatures of Windows files; Protected Root
Service, which adds and removes Trusted Root Certification Authority
certificates from this computer; and Key Service, which helps enroll
this computer for certificates. If this service is stopped, these
management services will not function properly. If this service is
disabled, any services that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs

Name: DefWatch
Description:
Startup Mode: Auto
Run from: C:\PROGRA~1\SYMANT~1\DefWatch.exe

Name: Dhcp
Description: Manages network configuration by registering and updating
IP addresses and DNS names.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: dmserver
Description: Detects and monitors new hard disk drives and sends disk
volume information to Logical Disk Manager Administrative Service for
configuration. If this service is stopped, dynamic disk status and
configuration information may become out of date. If this service is
disabled, any services that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Dnscache
Description: Resolves and caches Domain Name System (DNS) names for
this computer. If this service is stopped, this computer will not be
able to resolve DNS names and locate Active Directory domain
controllers. If this service is disabled, any services that explicitly
depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k NetworkService

Name: ERSvc
Description: Allows error reporting for services and applictions
running in non-standard environments.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Eventlog
Description: Enables event log messages issued by Windows-based
programs and components to be viewed in Event Viewer. This service
cannot be stopped.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\services.exe

Name: EventSystem
Description: Supports System Event Notification Service (SENS), which
provides automatic distribution of events to subscribing Component
Object Model (COM) components. If the service is stopped, SENS will
close and will not be able to provide logon and logoff notifications.
If this service is disabled, any services that explicitly depend on it
will fail to start.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: FastUserSwitchingCompatibility
Description: Provides management for applications that require
assistance in a multiple user environment.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: helpsvc
Description: Enables Help and Support Center to run on this computer.
If this service is stopped, Help and Support Center will be
unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: lanmanserver
Description: Supports file, print, and named-pipe sharing over the
network for this computer. If this service is stopped, these functions
will be unavailable. If this service is disabled, any services that
explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: lanmanworkstation
Description: Creates and maintains client network connections to remote
servers. If this service is stopped, these connections will be
unavailable. If this service is disabled, any services that explicitly
depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: LmHosts
Description: Enables support for NetBIOS over TCP/IP (NetBT) service
and NetBIOS name resolution.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k LocalService

Name: Messenger
Description: Transmits net send and Alerter service messages between
clients and servers. This service is not related to Windows Messenger.
If this service is stopped, Alerter messages will not be transmitted.
If this service is disabled, any services that explicitly depend on it
will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Netman
Description: Manages objects in the Network and Dial-Up Connections
folder, in which you can view both local area network and remote
connections.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Nla
Description: Collects and stores network configuration and location
information, and notifies applications when this information changes.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Norton AntiVirus Server
Description: Provides real-time virus scanning, reporting, and
management functionality for Symantec Client Security.
Startup Mode: Auto
Run from: C:\PROGRA~1\SYMANT~1\Rtvscan.exe

Name: NVSvc
Description:
Startup Mode: Auto
Run from: C:\WINDOWS\System32\nvsvc32.exe

Name: PlugPlay
Description: Enables a computer to recognize and adapt to hardware
changes with little or no user input. Stopping or disabling this
service will result in system instability.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\services.exe

Name: PolicyAgent
Description: Manages IP security policy and starts the ISAKMP/Oakley
(IKE) and the IP security driver.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\lsass.exe

Name: ProtectedStorage
Description: Provides protected storage for sensitive data, such as
private keys, to prevent access by unauthorized services, processes, or
users.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\lsass.exe

Name: RasMan
Description: Creates a network connection.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: RemoteRegistry
Description: Enables remote users to modify registry settings on this
computer. If this service is stopped, the registry can be modified only
by users on this computer. If this service is disabled, any services
that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k LocalService

Name: RpcSs
Description: Provides the endpoint mapper and other miscellaneous RPC
services.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost -k rpcss

Name: SamSs
Description: Stores security information for local user accounts.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\lsass.exe

Name: Schedule
Description: Enables a user to configure and schedule automated tasks
on this computer. If this service is stopped, these tasks will not be
run at their scheduled times. If this service is disabled, any services
that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: seclogon
Description: Enables starting processes under alternate credentials. If
this service is stopped, this type of logon access will be unavailable.
If this service is disabled, any services that explicitly depend on it
will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: SENS
Description: Tracks system events such as Windows logon, network, and
power events. Notifies COM+ Event System subscribers of these events.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs

Name: ShellHWDetection
Description:
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Spooler
Description: Loads files to memory for later printing.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\spoolsv.exe

Name: srservice
Description: Performs system restore functions. To stop service, turn
off System Restore from the System Restore tab in My
Computer->Properties
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: SSDPSRV
Description: Enables discovery of UPnP devices on your home network.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k LocalService

Name: TapiSrv
Description: Provides Telephony API (TAPI) support for programs that
control telephony devices and IP based voice connections on the local
computer and, through the LAN, on servers that are also running the
service.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: TermService
Description: Allows multiple users to be connected interactively to a
machine as well as the display of desktops and applications to remote
computers. The underpinning of Remote Desktop (including RD for
Administrators), Fast User Switching, Remote Assistance, and Terminal
Server.
Startup Mode: Manual
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: Themes
Description: Provides user experience theme management.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: TrkWks
Description: Maintains links between NTFS files within a computer or
across computers in a network domain.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs

Name: uploadmgr
Description: Manages synchronous and asynchronous file transfers
between clients and servers on the network. If this service is stopped,
synchronous and asynchronous file transfers between clients and servers
on the network will not occur. If this service is disabled, any
services that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: W32Time
Description: Maintains date and time synchronization on all clients and
servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any
services that explicitly depend on it will fail to start.

Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: WebClient
Description: Enables Windows-based programs to create, access, and
modify Internet-based files. If this service is stopped, these
functions will not be available. If this service is disabled, any
services that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k LocalService

Name: winmgmt
Description: Provides a common interface and object model to access
management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software
will not function properly. If this service is disabled, any services
that explicitly depend on it will fail to start.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs

Name: wuauserv
Description: Enables the download and installation of Windows updates.
If this service is disabled, this computer will not be able to use the
Automatic Updates feature or the Windows Update Web site.
Startup Mode: Auto
Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs

Name: WZCSVC
Description: Provides automatic configuration for the 802.11 adapters
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs

Name: WmdmPmSp
Description: Retrieves the serial number of any portable music player
connected to your computer
Startup Mode: Auto
Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs
 
Hi Ann,

Has Doug replied to your post here? He generally doesn't work this board.

Start here:

svchosta.exe
http://www.google.com/search?hl=en&q=SVCHOSTA.EXE&btnG=Google+Search

In the meantime, clean your system:

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update each program, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/housecall/start_corp.asp


--
All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com
 
Back
Top