System 32 Folder (Repost)

S

Steve

Here are the registry folders:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersi
on\Run]
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"MsnMsgr"="\"C:\\Program Files\\MSN
Messenger\\MsnMsgr.Exe\" /background"
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"MoneyStartUp10.0"="\"C:\\Program Files\\Microsoft
Money\\System\\Activation.exe\""
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH
Jukebox\\mm_tray.exe"
"MCAgentExe"="c:\\PROGRA~1
\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1
\\mcafee.com\\agent\\McUpdate.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD
Creator 5\\DirectCD\\DirectCD.exe\""
"VirusScan Online"="\"c:\\PROGRA~1
\\mcafee.com\\vso\\mcvsshld.exe\""
"VSOCheckTask"="\"c:\\PROGRA~1
\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"
"ConMgr.exe"="\"C:\\Program Files\\EarthLink 5.0
\\conmgr.exe\""
"RealTray"="C:\\Program
Files\\Real\\RealPlayer\\RealPlay.exe
SYSTEMBOOTHIDEPLAYER"
"mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH
Jukebox\\mmtask.exe"
"2LRX2W83X2T3MQ"="C:\\WINDOWS\\System32\\Zbo1L.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Belt"="C:\\WINDOWS\\Belt.exe"
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00
"updater"="C:\\Program Files\\Common
files\\updater\\wupdater.exe"
"o"="C:\\WINDOWS\\System32\\twetmr.exe"
"couponsandoffers"="wjview /cp:p \"C:\\Program
Files\\couponsandoffers\\System\\Code\" Main lp:
\"C:\\Program Files\\couponsandoffers\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32
\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"HPHUPD05"="C:\\Program Files\\Hewlett-Packard\\{45B6180B-
DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"HP Component Manager"="\"C:\\Program
Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-
Packard\\HP Software Update\\HPWuSchd.exe\""
"HPHmon05"="C:\\WINDOWS\\System32\\hphmon05.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"zzb"=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,\

53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,7a,0
0,7a,00,62,00,2e,\
00,65,00,78,00,65,00,00,00
"Bargains"="C:\\Program Files\\Bargain
Buddy\\bin\\bargains.exe"
"msbb"="C:\\WINDOWS\\msbb.exe"
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1
\\MskAgent.exe"
"McAfee Guardian"="C:\\Program Files\\McAfee\\McAfee
Shared Components\\Guardian\\CMGrdian.exe /SU"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1
\\MSKDetct.exe /startup"
"MPFTray"="C:\\PROGRA~1\\McAfee.com\\PERSON~1
\\MpfTray.exe"
"CleanUp"="C:\\PROGRA~1
\\McAfee.com\\Shared\\mcappins.exe /v=3 /cleanup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MSFS]
"Installed"="1"




Subject: Re: System32 Folder
From: "Rick \"Nutcase\" Rogers" <[email protected]> Sent:
5/9/2004 7:21:26 PM




Hi Steve,

Please see:

System32 Folder Opens When Logging on to Windows
http://support.microsoft.com/?kbid=170086

Also, start/run msconfig, and see if there is a line that
loads /L:ENG. It
comes from a SoundBlaster Audigy driver, and it can cause
this problem as
well. If it exists, use the registry fix from MVP Kelly:

Line 260 on the right:
http://www.kellys-korner-xp.com/xp_tweaks.htm

It's far easier than mucking about in the registry. The
problem can also be
caused by other incorrectly built registry strings. So,
if the first two
steps don't help you, could you please export and post
the contents of these
keys in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersio
n\Run

To do this, start/run regedit, expand the branches to
each key (do this one
at a time). Click on the key, then on file/export. Give
it any name, then
save to the desktop. Once you have saved both keys, close
the registry
editor. Right-click one of the saved files on the
desktop, choose edit, it
should open in notepad. Click edit/select all/edit/copy.
Open a response to
this post and click in the message text area. Hit ctrl+v
to paste the
contents. Repeat for the other saved key, then send the
post for
examination.

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Windows
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone



message
When I sign on as a user, the System32 folder opens each
time, and stays open. Does anyone know how to get the
system to not open that folder?


..
 
R

Rick \Nutcase\ Rogers

Hi Steve,

Ok, let's see what we have here (comments inline):
"2LRX2W83X2T3MQ"="C:\\WINDOWS\\System32\\Zbo1L.exe

Likely a trojan file, something you want to remove.
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
Spyware


Spyware

"updater"="C:\\Program Files\\Common
files\\updater\\wupdater.exe"

You have a bit of a parasite on the system, please see this link:
http://www.safersite.com/pestinfo/k/keenvalue.asp
"o"="C:\\WINDOWS\\System32\\twetmr.exe"

Likely another trojan.
"couponsandoffers"="wjview /cp:p \"C:\\Program
Files\\couponsandoffers\\System\\Code\" Main lp:
\"C:\\Program Files\\couponsandoffers\""

More spyware.
"Bargains"="C:\\Program Files\\Bargain
Buddy\\bin\\bargains.exe"

And more.
"msbb"="C:\\WINDOWS\\msbb.exe"

Web3000 garbage (spyware)

Suggest you run Adaware from www.lavasoft.de to help clean up the garbage.
Boot to Safe mode and delete the trojans and the references to them in the
registry, probably under these keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Then restart the system normally.

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Windows
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top