PC Review Forums Newsgroups Hardware Anti-Virus removing system32.exe from registry

Reply

removing system32.exe from registry

 
Thread Tools Rate Thread
Old 10-01-2004, 09:54 PM   #1
Jimbob
Guest
 
Posts: n/a
Default removing system32.exe from registry


I have removed a virus from my PC (sorry, don't know which one). I
uninstalled a load of spyware, cleaned up my system with everything I could,
disabled System Restore (I have Windows XP) and ran a complete, updated
virus check and everything seems OK now but I get a message at startup that
windows can't find System32.exe. I know this is a file created by the virus
but there is no reference to it in the usual places (eg Win.ini, Startup).
However there is only one reference in the registry in
HKey_LocalMachine/Software/Microsoft/Windows NT/CurrentVersion/Winlogon

The right panel says

Shell Reg_sz Explorer.exe C:\Windows\System32.exe

I assume this is causing my startup message. Am I safe to delete this key?
Or are there other things I should do first?

Evi


  Reply With Quote
Old 10-01-2004, 10:20 PM   #2
John Coutts
Guest
 
Posts: n/a
Default Re: removing system32.exe from registry

In article <pw_Lb.848$Ez4.565@newsfep1-gui.server.ntli.net>,
jimbob4evaSpamTrap@hotmail.com says...
>
>I have removed a virus from my PC (sorry, don't know which one). I
>uninstalled a load of spyware, cleaned up my system with everything I could,
>disabled System Restore (I have Windows XP) and ran a complete, updated
>virus check and everything seems OK now but I get a message at startup that
>windows can't find System32.exe. I know this is a file created by the virus
>but there is no reference to it in the usual places (eg Win.ini, Startup).
>However there is only one reference in the registry in
>HKey_LocalMachine/Software/Microsoft/Windows NT/CurrentVersion/Winlogon
>
>The right panel says
>
>Shell Reg_sz Explorer.exe C:\Windows\System32.exe
>
>I assume this is causing my startup message. Am I safe to delete this key?
>Or are there other things I should do first?
>
>Evi

****************** REPLY SEPARATER ***********************
Found this on a google search. Cannot verify the method, but system32.exe is
definitely not a system file on XP.
-------------------------------------------------------------------
Posted by Swaroop Kumar [find other messages by Swaroop Kumar]

system32.exe is a virus. To get rid of the problem... click
start>run>regedit.... go to
HKey_local_machine\software\microsoft\windowsNT\currentVersion\WinLogon.

On the right hand side you will find a value for SHELL "Explorer.exe
C:\WINDOWS\System32\System32.exe". Here..delete
"C:\WINDOWS\System32\System32.exe" so as to leave just Explorer.exe. Then boot
to the safemode and delete the file "C:\WINDOWS\System32\System32.exe". This
will remove the worm from the computer. Take care!
------------------------------------------------------------------

  Reply With Quote
Old 10-01-2004, 10:21 PM   #3
David W. Hodgins
Guest
 
Posts: n/a
Default Re: removing system32.exe from registry

On Sat, 10 Jan 2004 21:54:26 -0000, Jimbob <jimbob4evaSpamTrap@hotmail.com> wrote:

> virus check and everything seems OK now but I get a message at startup that
> windows can't find System32.exe. I know this is a file created by the virus


Google is your friend<G>!

According to http://www.liutilities.com/products...brary/system32/
it's safe to delete the registry key.

Regards, Dave Hodgins

--
Change nomail.afraid.org to rogers.com to reply by email.
(nomail.afraid.org has been set up specfically for
use in usenet. Feel free to use it yourself.)
  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off