system32 pop up window on start up

  • Thread starter Thread starter Tony
  • Start date Start date
T

Tony

A window that displays the contents of the system32
directory pops up on my terminal on startup. After
deleting this window it will pop up again for a 2nd time.
After deleting the 2nd pop up it will not occur again
until I reboot the system.

How can I prevent this pop up from happening?

Thanks
 
Greetings --

This can be caused by a blank entry, such as can be left behind by
an incomplete program removal, in the
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and/or
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run keys.

System32 Folder Opens When Logging on to Windows
http://support.microsoft.com/default.aspx?scid=kb;en-us;170086


Bruce Chambers

--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
Hi Tony,

Please see:

System32 Folder Opens When Logging on to Windows
http://support.microsoft.com/?kbid=170086

Also, start/run msconfig, and see if there is a line that loads /L:ENG. If
so, disable it. It comes from a SoundBlaster Audigy driver, but should not
affect that hardware. You can also repair the registry entry if you like by
removing the leading space in the string that loads it.

However, it can also be caused by other incorrectly built registry strings.
Could you please export and post the contents of these keys in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

To do this, start/run regedit, expand the branches to each key (do this one
at a time). Click on the key, then on file/export. Give it any name, then
save to the desktop. Once you have saved both keys, close the registry
editor. Right-click one of the saved files on the desktop, choose edit, it
should open in notepad. Click edit/select all/edit/copy. Open a response to
this post and click in the message text area. Hit ctrl+v to paste the
contents. Repeat for the other saved key, then send the post for
examination.

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Win9x
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone
 
Here is the contents of the two register keys: it looks
like the ATI program has a null entry, is this the
problem? what should I do with it? Thanks

FIRST KEY:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersi
on\Run]
"Tray Temperature"="C:\\Program
Files\\AWS\\WeatherBug\\WeatherBug.exe 1"
"MSMSGS"="\"C:\\Program
Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"ATI Launchpad"=""
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00

==========================================================

SECOND KEY

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run]
"{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"="rundll32.exe
C:\\WINDOWS\\System32\\stlbupdt.DLL,DllRunMain"
"WINSTA~1.EXE"="C:\\WINDOWS\\System\\WINSTA~1.EXE -b"
"SystemTray"="SysTray.Exe"
"Rundll16"="C:\\WINDOWS\\RunDll16.exe"
"rrklkfyq"="C:\\WINDOWS\\System32\\rrklkfyq.exe"
"RDLL"="RunDll16.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32
\\NvCpl.dll,NvStartup"
"MS Updates"="C:\\WINDOWS\\mscache.exe"
"IPInSightMonitor 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPMon32.exe\""
"IPInSightLAN 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPClient.exe\" -l"
"IntelliType"="\"C:\\Program Files\\Microsoft
Hardware\\Keyboard\\type32.exe\""
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"1A:Stardock TrayMonitor"="\"C:\\Program Files\\Common
Files\\Stardock\\TrayServer.exe\""
"WinFavorites"="c:\\program
files\\winfavorites\\WinFavorites.exe1"
"iTunesHelper"="C:\\Program
Files\\iTunes\\iTunesHelper.exe"
"iehelper"="C:\\Program Files\\syslaunch.exe"
"slmss"="C:\\Program Files\\Common
Files\\slmss\\slmss.exe"
"Mwsvm"="C:\\WINDOWS\\mwsvm.exe"
"absr"="C:\\WINDOWS\\mwsvm.exe "
"nvid"="C:\\WINDOWS\\System32\\nvtbtwpk.exe"
"TkBellExe"="\"C:\\Program Files\\Common
Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00
"UserFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,
\

6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,0
0,33,00,32,00,5c,\

00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,00,2
0,00,2d,00,75,00,\
00,00
"KernelFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\

00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6
d,00,33,00,32,00,\

5c,00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,0
0,20,00,2d,00,6b,\
00,00,00
"QuickTime Task"="\"C:\\Program
Files\\QuickTime\\qttask.exe\" -atboottime"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program
Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash
Screen\\CTEaxSpl.EXE /run"
"OfficeScanNT Monitor"="\"C:\\program files\\OfficeScan
NT\\pccntmon.exe\""
"iPodWatcher"="C:\\Program Files\\iPod_011704
\\Bin\\iPodWatcher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MSFS]
"Installed"="1"
 
Hi Tony,

Click on the strng in the right pane and delete it. Then you may also want
to remove these, as they are viruses. You will likely need to restart in
Safe mode to delete the strings and the infecting files thenselves.
"rrklkfyq"="C:\\WINDOWS\\System32\\rrklkfyq.exe"
"Mwsvm"="C:\\WINDOWS\\mwsvm.exe"
"absr"="C:\\WINDOWS\\mwsvm.exe "
"nvid"="C:\\WINDOWS\\System32\\nvtbtwpk.exe"
"slmss"="C:\\Program Files\\Common Files\\slmss\\slmss.exe"

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Win9x
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone



Tony said:
Here is the contents of the two register keys: it looks
like the ATI program has a null entry, is this the
problem? what should I do with it? Thanks

FIRST KEY:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersi
on\Run]
"Tray Temperature"="C:\\Program
Files\\AWS\\WeatherBug\\WeatherBug.exe 1"
"MSMSGS"="\"C:\\Program
Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"ATI Launchpad"=""
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00

==========================================================

SECOND KEY

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run]
"{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"="rundll32.exe
C:\\WINDOWS\\System32\\stlbupdt.DLL,DllRunMain"
"WINSTA~1.EXE"="C:\\WINDOWS\\System\\WINSTA~1.EXE -b"
"SystemTray"="SysTray.Exe"
"Rundll16"="C:\\WINDOWS\\RunDll16.exe"
"rrklkfyq"="C:\\WINDOWS\\System32\\rrklkfyq.exe"
"RDLL"="RunDll16.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32
\\NvCpl.dll,NvStartup"
"MS Updates"="C:\\WINDOWS\\mscache.exe"
"IPInSightMonitor 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPMon32.exe\""
"IPInSightLAN 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPClient.exe\" -l"
"IntelliType"="\"C:\\Program Files\\Microsoft
Hardware\\Keyboard\\type32.exe\""
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"1A:Stardock TrayMonitor"="\"C:\\Program Files\\Common
Files\\Stardock\\TrayServer.exe\""
"WinFavorites"="c:\\program
files\\winfavorites\\WinFavorites.exe1"
"iTunesHelper"="C:\\Program
Files\\iTunes\\iTunesHelper.exe"
"iehelper"="C:\\Program Files\\syslaunch.exe"
"slmss"="C:\\Program Files\\Common
Files\\slmss\\slmss.exe"
"Mwsvm"="C:\\WINDOWS\\mwsvm.exe"
"absr"="C:\\WINDOWS\\mwsvm.exe "
"nvid"="C:\\WINDOWS\\System32\\nvtbtwpk.exe"
"TkBellExe"="\"C:\\Program Files\\Common
Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00
"UserFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,
\

6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,0
0,33,00,32,00,5c,\

00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,00,2
0,00,2d,00,75,00,\
00,00
"KernelFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\

00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6
d,00,33,00,32,00,\

5c,00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,0
0,20,00,2d,00,6b,\
00,00,00
"QuickTime Task"="\"C:\\Program
Files\\QuickTime\\qttask.exe\" -atboottime"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program
Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash
Screen\\CTEaxSpl.EXE /run"
"OfficeScanNT Monitor"="\"C:\\program files\\OfficeScan
NT\\pccntmon.exe\""
"iPodWatcher"="C:\\Program Files\\iPod_011704
\\Bin\\iPodWatcher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MSFS]
"Installed"="1"



-----Original Message-----

A window that displays the contents of the system32
directory pops up on my terminal on startup. After
deleting this window it will pop up again for a 2nd time.
After deleting the 2nd pop up it will not occur again
until I reboot the system.

How can I prevent this pop up from happening?

Thanks


.
 
Check:
Start/Run/control folders/View/Uncheck Restore previous folder windows
at logon

More information:
Do you have a Sound Blaster Audigy 2 sound card?
www.kellys-korner.com/xp_tweaks.htm, Line #260
System32 Folder Opens Upon Boot
http://support.microsoft.com/default.aspx?scid=kb;[LN];170086
System32 Folder Opens When Logging on to Windows XP, Windows 2000, or
Windows
NT 4.0


Akira said:
Recently I have a problem with my computer which runs on Windows XP Home,
I'd like someone here to help me. Each time windows start, the
c:\windows\system32 folder pops-up, Is there a way to stop this folder from
displaying ?

Thanks in advance.
Marks

Tony said:
Here is the contents of the two register keys: it looks
like the ATI program has a null entry, is this the
problem? what should I do with it? Thanks

FIRST KEY:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersi
on\Run]
"Tray Temperature"="C:\\Program
Files\\AWS\\WeatherBug\\WeatherBug.exe 1"
"MSMSGS"="\"C:\\Program
Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"ATI Launchpad"=""
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00

==========================================================

SECOND KEY

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run]
"{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"="rundll32.exe
C:\\WINDOWS\\System32\\stlbupdt.DLL,DllRunMain"
"WINSTA~1.EXE"="C:\\WINDOWS\\System\\WINSTA~1.EXE -b"
"SystemTray"="SysTray.Exe"
"Rundll16"="C:\\WINDOWS\\RunDll16.exe"
"rrklkfyq"="C:\\WINDOWS\\System32\\rrklkfyq.exe"
"RDLL"="RunDll16.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32
\\NvCpl.dll,NvStartup"
"MS Updates"="C:\\WINDOWS\\mscache.exe"
"IPInSightMonitor 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPMon32.exe\""
"IPInSightLAN 01"="\"C:\\Program Files\\Verizon
Online\\Visual IP InSight\\IPClient.exe\" -l"
"IntelliType"="\"C:\\Program Files\\Microsoft
Hardware\\Keyboard\\type32.exe\""
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"1A:Stardock TrayMonitor"="\"C:\\Program Files\\Common
Files\\Stardock\\TrayServer.exe\""
"WinFavorites"="c:\\program
files\\winfavorites\\WinFavorites.exe1"
"iTunesHelper"="C:\\Program
Files\\iTunes\\iTunesHelper.exe"
"iehelper"="C:\\Program Files\\syslaunch.exe"
"slmss"="C:\\Program Files\\Common
Files\\slmss\\slmss.exe"
"Mwsvm"="C:\\WINDOWS\\mwsvm.exe"
"absr"="C:\\WINDOWS\\mwsvm.exe "
"nvid"="C:\\WINDOWS\\System32\\nvtbtwpk.exe"
"TkBellExe"="\"C:\\Program Files\\Common
Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=hex
(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,
53,00,5c,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,00,00
"UserFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,
\

6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,0
0,33,00,32,00,5c,\

00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,00,2
0,00,2d,00,75,00,\
00,00
"KernelFaultCheck"=hex
(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\

00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6
d,00,33,00,32,00,\

5c,00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,0
0,20,00,2d,00,6b,\
00,00,00
"QuickTime Task"="\"C:\\Program
Files\\QuickTime\\qttask.exe\" -atboottime"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program
Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash
Screen\\CTEaxSpl.EXE /run"
"OfficeScanNT Monitor"="\"C:\\program files\\OfficeScan
NT\\pccntmon.exe\""
"iPodWatcher"="C:\\Program Files\\iPod_011704
\\Bin\\iPodWatcher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\Run\OptionalComponents\MSFS]
"Installed"="1"



-----Original Message-----

A window that displays the contents of the system32
directory pops up on my terminal on startup. After
deleting this window it will pop up again for a 2nd time.
After deleting the 2nd pop up it will not occur again
until I reboot the system.

How can I prevent this pop up from happening?

Thanks


.
 
Rick,

I didn't delete the ATI null entry yet. The reg info I
showed you was collected under my XP user login name. When
I looked at the same reg-keys while my son was logged in
(the sys32 window pops up for him also) I didn't see the
ATI null entry. Since he doesn't have this entry and the
same pop up problem happens for him too does this mean
that the ATI entry under my login is not the cause of the
sys32 pop up?

Thanks for your help
 
Hi Tony,

I answered privately, however I will repost here:

Clean out the keys loading the viruses first - they are the most major
concern. Once they are gone, the problem may right itself, this is a known
cause. To delete the strings (not keys) viruses, you click on the entry in
the right pane and hit <delete>. This must be done in Safe mode.

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Win9x
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top