fortypoundhead.com

When you start Windows XP, you receive 'Cannot find C:\Windows\System32\System32.exe'

Posted On 2005-11-1 by FortyPoundHead
Keywords: Windows XP System 32 Cannot Find
Tags:  
Views: 1377


The subject error message is indicative of an incomplete removal of the W32.KWBot.C.Worm virus from the registry.



To remove the virus from the registry:



01. Open Regedit.exe.



02. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



03. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



04. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



05. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



06. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



07. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



08. Delete the HKEY_Local_Machine\Software\Krypton key if it exists.



09. If the Shell Value Name, at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon does NOT contain the correct shell, Explorer.exe by default, change it.



10. Navigate to HKEY_CURRENT_USER\SOFTWARE\Kazaa\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



11. Navigate to HKEY_CURRENT_USER\SOFTWARE\iMesh\Client\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



12. Exit the Registry Editor.



13. Shutdown and restart Windows XP.






About the Author

FortyPoundHead has posted a total of 1974 articles.

 


Comments On This Post

No comments on this post yet!


Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:54.161.75.128

Before you can post, you need to prove you are human. If you log in, this test goes away.



Recent Forum Posts

List of Shady Characters
dwirch posted on April 25, 2017 at about 16:39 in Webmaster Stuff

Job Spammer: Bilal Uddin
dwirch posted on April 25, 2017 at about 11:00 in Spammers

Bug Fix: Contact Form Error
dwirch posted on April 21, 2017 at about 11:38 in Site News

Bug Fix: Ophion Time Tracker
dwirch posted on April 9, 2017 at about 11:30 in Site News

Job Spammer: Yogesh Kapadne
dwirch posted on March 31, 2017 at about 8:04 in Spammers

Job Spammer: Sathya Narayana
dwirch posted on March 15, 2017 at about 7:18 in Spammers