fortypoundhead.com

When you start Windows XP, you receive 'Cannot find C:\Windows\System32\System32.exe'

Posted On 2005-11-1 by FortyPoundHead
Keywords: Windows XP System 32 Cannot Find
Tags:  
Views: 1397


The subject error message is indicative of an incomplete removal of the W32.KWBot.C.Worm virus from the registry.



To remove the virus from the registry:



01. Open Regedit.exe.



02. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



03. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



04. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



05. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



06. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the SystemSAS Value Name exists, and contains the system32.exe data value, delete the Value Name.



07. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. If the CMD Value Name exists, and contains the cmd32.exe.exe data value, delete the Value Name.



08. Delete the HKEY_Local_Machine\Software\Krypton key if it exists.



09. If the Shell Value Name, at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon does NOT contain the correct shell, Explorer.exe by default, change it.



10. Navigate to HKEY_CURRENT_USER\SOFTWARE\Kazaa\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



11. Navigate to HKEY_CURRENT_USER\SOFTWARE\iMesh\Client\LocalContent. Delete any Value Names that reference the %Windir%\UserTemp or %Windir%\User32 folders.



12. Exit the Registry Editor.



13. Shutdown and restart Windows XP.






About the Author

FortyPoundHead has posted a total of 1974 articles.

 


Comments On This Post

No comments on this post yet!


Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:54.158.31.149

Before you can post, you need to prove you are human. If you log in, this test goes away.



Recent Forum Posts

Q&A borked
dwirch posted on June 27, 2017 at about 7:00 in Site News

SSL Now Active
dwirch posted on June 16, 2017 at about 8:40 in Site News

SSL Now Active
dwirch posted on June 13, 2017 at about 7:59 in Site News

Coding Archive?
dwirch posted on June 3, 2017 at about 12:54 in Site News

Job Spammer: Bharti Jigyasi
dwirch posted on June 2, 2017 at about 16:57 in Spammers

Coding Archive?
dwirch posted on May 25, 2017 at about 12:38 in Site News