fortypoundhead.com

When you start Windows XP, you receive 'Cannot find C:\Windows\System32\System32.exe'

Primary Category =

Posted On 2005-11-1 by FortyPoundHead
Keywords: Windows XP System 32 Cannot Find
Tags:  
Views: 1369
Rating: / 5.00

  • 1
  • 2
  • 3
  • 4
  • 5

 

The subject error message is indicative of an incomplete removal of the W32.KWBot.C.Worm virus from the registry.



To remove the virus from the registry:



01. Open Regedit.exe.



02. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



03. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



04. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



05. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



06. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



07. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



08. Delete the HKEY_Local_Machine\Software\Krypton key if it exists.



09. If the Shell Value Name, at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon does NOT contain the correct shell, Explorer.exe by default, change it.



10. Navigate to HKEY_CURRENT_USER\SOFTWARE\Kazaa\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



11. Navigate to HKEY_CURRENT_USER\SOFTWARE\iMesh\Client\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



12. Exit the Registry Editor.



13. Shutdown and restart Windows XP.





About the Author

FortyPoundHead has posted a total of 1975 articles.

You can find more information from FortyPoundHead by visiting .

Comments On This Post

No comments on this post yet!

 

Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:54.163.159.27

Before you can post, you need to prove you are human. If you log in, this test goes away.