F
FUBARinSFO
Hi folks:
In the course of tracking down the cause of external commands not
executing in command windows, I fixed the problem by changing the data
type of the PATH environment variable in HKEY_LOCAL_MACHINE\SYSTEM
\CurrentControlSet\Control\Session Manager\Environment from REG_SZ to
REG_EXPAND_SZ (thank you Bill Stewart at http://internet.cybermesa.com/~bstewart/cmdprompt.html#6
and Wesley Vogel here)
However, it turns out on further inspection that there are some,
perhaps many (4 in one system, 637 in another) registry entries
containing the string '%SystemRoot%' or other expansion environment
variable in its with data type REG_SZ. I've inluded smoe of the data
below in this note.
1. Should all the entries with data type REG_SZ data be changed to
REG_EXPAND_SZ?
2. In the cases where therer are hundreds, is there any tool to do
this with?
3. Does anybody have any idea how this might have come about?
Thank you in advance for your help.
-- Roy Zider
working on systemroot problem
5:29 PM 6/21/2007 lsz
Key name
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}
Name (Default)
Type REG_SZ
Data Lauguage bar
Name MenuTextPUI
Type REG_SZ
Data @%SystemRoot%\System32\msutb.dll,-325
Above key as exported (file K7NFULL1.TXT, ANSI now not Unicode)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
Searching K7N registry....
Using exported file K7NFULL1.TXT
Search term: %;
Found 1 hit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
Search term: %\\\
No hits
Search term: %\\
4 hits:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon]
@="%SystemRoot%\\system32\\url.dll,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Intelligent Search\RNL\1.0]
"LoggingWanted"=dword:00000000
"LoggingPath"="%TEMP%\\rnl_log.txt"
Check out the four keys for data type -- all are REG_SZ.
Now search current TOOT registry ...
Use file regfull.txt
Search term: %;
Found 1 hit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
Search term: %\\\
No hits
Search term: %\\
637 hits:
Showing first ten only:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\WINWORD.EXE
\TaskbarExceptionsIcon
s\explorer.exe,16]
@="%ProgramFiles%\\Microsoft Office\\Office10\\OUTLOOK.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}]
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon]
@="%SystemRoot%\\system32\\url.dll,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}]
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"Exec"="%windir%\\Network Diagnostic\\xpnetdiag.exe"
"MenuText"="@xpsp3res.dll,-20001"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control
Panel\Extended Properties\{305CA226-D286-468e-B848-2B2E8E697B74} 2]
"%SystemRoot%\\system32\\Firewall.cpl"="3,10"
"%SystemRoot%\\system32\\wscui.cpl"=dword:ffffffff
"%SystemRoot%\\system32\\NetSetup.cpl"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft
Shared\\Speech\\sapi.cpl"=dword:00000004
"%SystemRoot%\\System32\\wuaucpl.cpl"=dword:0000000a
"%SystemRoot%\\system32\\appwiz.cpl"=dword:00000008
"%SystemRoot%\\system32\\access.cpl"=dword:00000007
"%SystemRoot%\\system32\\bthprops.cpl"="2,3"
"%SystemRoot%\\system32\\desk.cpl"=dword:00000001
"%SystemRoot%\\system32\\hdwwiz.cpl"=dword:ffffffff
"%SystemRoot%\\system32\\inetcpl.cpl"="3,10"
"%SystemRoot%\\system32\\intl.cpl"=dword:00000006
"%SystemRoot%\\system32\\irprops.cpl"=dword:00000002
"%SystemRoot%\\system32\\joy.cpl"=dword:00000002
"%SystemRoot%\\system32\\main.cpl"=dword:00000002
"%SystemRoot%\\system32\\mmsys.cpl"=dword:00000004
"%SystemRoot%\\system32\\ncpa.cpl"=dword:00000003
"%SystemRoot%\\system32\\nwc.cpl"=dword:00000000
"%SystemRoot%\\system32\\nusrmgr.cpl"=dword:00000009
"%SystemRoot%\\system32\\odbccp32.cpl"=dword:00000000
"%SystemRoot%\\system32\\powercfg.cpl"=dword:00000005
"%SystemRoot%\\system32\\sysdm.cpl"="5"
"%SystemRoot%\\system32\\telephon.cpl"=dword:00000002
"%SystemRoot%\\system32\\timedate.cpl"=dword:00000006
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSCDBurningOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,35,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17169"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17170"
"InvokeProgID"="Folder"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSOpenFolder]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,35,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17154"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17155"
"InvokeProgID"="Folder"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSPrintPicturesOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,31,00,37,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17158"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17159"
"InvokeProgID"="Applications\\shimgvw.dll"
"InvokeVerb"="print"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSSHAudioDevHandler]
@=""
"Action"="@%SystemRoot%\\system32\\audiodev.dll,-500"
"Provider"="@%SystemRoot%\\system32\\audiodev.dll,-501"
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
61,00,75,00,64,00,69,00,6f,00,64,00,65,00,76,00,2e,00,64,00,6c,00,6c,
00,2c,\
00,2d,00,35,00,30,00,00,00
"ProgID"="Shell.HWEventHandlerShellExecute"
"InitCmdLine"="::{21EC2020-3AEA-1069-A2DD-08002B30309D}\\::
{640167b4-59b0-47a6-b335
-a6b3c0695aea}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSShowPicturesOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,32,00,34,00,39,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17156"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17157"
"InvokeProgID"="Shell.AutoplayForSlideShow.1"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSTakeNoAction]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,33,00,33,00,38,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17168"
"Provider"="<TakeNoAction>"
"ProgID"="Shell.AutoplaySpecial"
In the course of tracking down the cause of external commands not
executing in command windows, I fixed the problem by changing the data
type of the PATH environment variable in HKEY_LOCAL_MACHINE\SYSTEM
\CurrentControlSet\Control\Session Manager\Environment from REG_SZ to
REG_EXPAND_SZ (thank you Bill Stewart at http://internet.cybermesa.com/~bstewart/cmdprompt.html#6
and Wesley Vogel here)
However, it turns out on further inspection that there are some,
perhaps many (4 in one system, 637 in another) registry entries
containing the string '%SystemRoot%' or other expansion environment
variable in its with data type REG_SZ. I've inluded smoe of the data
below in this note.
1. Should all the entries with data type REG_SZ data be changed to
REG_EXPAND_SZ?
2. In the cases where therer are hundreds, is there any tool to do
this with?
3. Does anybody have any idea how this might have come about?
Thank you in advance for your help.
-- Roy Zider
working on systemroot problem
5:29 PM 6/21/2007 lsz
Key name
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}
Name (Default)
Type REG_SZ
Data Lauguage bar
Name MenuTextPUI
Type REG_SZ
Data @%SystemRoot%\System32\msutb.dll,-325
Above key as exported (file K7NFULL1.TXT, ANSI now not Unicode)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
Searching K7N registry....
Using exported file K7NFULL1.TXT
Search term: %;
Found 1 hit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
Search term: %\\\
No hits
Search term: %\\
4 hits:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon]
@="%SystemRoot%\\system32\\url.dll,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Intelligent Search\RNL\1.0]
"LoggingWanted"=dword:00000000
"LoggingPath"="%TEMP%\\rnl_log.txt"
Check out the four keys for data type -- all are REG_SZ.
Now search current TOOT registry ...
Use file regfull.txt
Search term: %;
Found 1 hit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
Search term: %\\\
No hits
Search term: %\\
637 hits:
Showing first ten only:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\WINWORD.EXE
\TaskbarExceptionsIcon
s\explorer.exe,16]
@="%ProgramFiles%\\Microsoft Office\\Office10\\OUTLOOK.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{540D8A8B-1C3F-4E32-8132-530F6A502090}]
@="Language bar"
"MenuTextPUI"="@%SystemRoot%\\System32\\msutb.dll,-325"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon]
@="%SystemRoot%\\system32\\url.dll,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HTMLHelp\1.x]
"EnforcedDirectories"="%WINDIR%;%ProgramFiles%\\Movie Maker"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}]
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"Exec"="%windir%\\Network Diagnostic\\xpnetdiag.exe"
"MenuText"="@xpsp3res.dll,-20001"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control
Panel\Extended Properties\{305CA226-D286-468e-B848-2B2E8E697B74} 2]
"%SystemRoot%\\system32\\Firewall.cpl"="3,10"
"%SystemRoot%\\system32\\wscui.cpl"=dword:ffffffff
"%SystemRoot%\\system32\\NetSetup.cpl"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft
Shared\\Speech\\sapi.cpl"=dword:00000004
"%SystemRoot%\\System32\\wuaucpl.cpl"=dword:0000000a
"%SystemRoot%\\system32\\appwiz.cpl"=dword:00000008
"%SystemRoot%\\system32\\access.cpl"=dword:00000007
"%SystemRoot%\\system32\\bthprops.cpl"="2,3"
"%SystemRoot%\\system32\\desk.cpl"=dword:00000001
"%SystemRoot%\\system32\\hdwwiz.cpl"=dword:ffffffff
"%SystemRoot%\\system32\\inetcpl.cpl"="3,10"
"%SystemRoot%\\system32\\intl.cpl"=dword:00000006
"%SystemRoot%\\system32\\irprops.cpl"=dword:00000002
"%SystemRoot%\\system32\\joy.cpl"=dword:00000002
"%SystemRoot%\\system32\\main.cpl"=dword:00000002
"%SystemRoot%\\system32\\mmsys.cpl"=dword:00000004
"%SystemRoot%\\system32\\ncpa.cpl"=dword:00000003
"%SystemRoot%\\system32\\nwc.cpl"=dword:00000000
"%SystemRoot%\\system32\\nusrmgr.cpl"=dword:00000009
"%SystemRoot%\\system32\\odbccp32.cpl"=dword:00000000
"%SystemRoot%\\system32\\powercfg.cpl"=dword:00000005
"%SystemRoot%\\system32\\sysdm.cpl"="5"
"%SystemRoot%\\system32\\telephon.cpl"=dword:00000002
"%SystemRoot%\\system32\\timedate.cpl"=dword:00000006
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSCDBurningOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,35,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17169"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17170"
"InvokeProgID"="Folder"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSOpenFolder]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,35,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17154"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17155"
"InvokeProgID"="Folder"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSPrintPicturesOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,31,00,37,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17158"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17159"
"InvokeProgID"="Applications\\shimgvw.dll"
"InvokeVerb"="print"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSSHAudioDevHandler]
@=""
"Action"="@%SystemRoot%\\system32\\audiodev.dll,-500"
"Provider"="@%SystemRoot%\\system32\\audiodev.dll,-501"
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
61,00,75,00,64,00,69,00,6f,00,64,00,65,00,76,00,2e,00,64,00,6c,00,6c,
00,2c,\
00,2d,00,35,00,30,00,00,00
"ProgID"="Shell.HWEventHandlerShellExecute"
"InitCmdLine"="::{21EC2020-3AEA-1069-A2DD-08002B30309D}\\::
{640167b4-59b0-47a6-b335
-a6b3c0695aea}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSShowPicturesOnArrival]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,32,00,34,00,39,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17156"
"Provider"="@%SystemRoot%\\system32\\SHELL32.dll,-17157"
"InvokeProgID"="Shell.AutoplayForSlideShow.1"
"InvokeVerb"="open"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\AutoplayHand
lers\Handlers\MSTakeNoAction]
"DefaultIcon"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,
00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,
00,33,00,32,00,5c,00,\
53,00,48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,
00,2d,\
00,33,00,33,00,38,00,00,00
"Action"="@%SystemRoot%\\system32\\SHELL32.dll,-17168"
"Provider"="<TakeNoAction>"
"ProgID"="Shell.AutoplaySpecial"