Announcement

Collapse
No announcement yet.

System32 Folder Opens at Startup

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Re: System32 Folder Opens at Startup

    Hi guys!

    Still having a hard time with this System32 folder on Windows XP Professional. I have taken the following troubleshooting steps:
    1. Followed the instructions in MS KB article 170086 - was unable to find the ActiveMovie File Extensions or the SystemTray registry values.
    2. Checked msconfig for an "\L:ENG" entry - none exists
    3. Edited the HKLM and HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry keys as per the following article:
      http://www.ieinfosite.co.uk/tip_view.asp?id=106
    4. Finally, ran HijackThis and saved the log (please see the end of this posting)
    Other strange things that are taking place are (and I have no idea whether they are at all related):
    1. Extremely long logoff time (about 1.5 min....unusual on a new machine)
    2. OS does not save the last person to log in ID
    3. I am unable to save my MSN Password credential settings
    If you are still reading this, thank you so much for your patience!!
    If you know the answer, THANK YOU even more for being an ubergenius!


    icastrillo

    HijackThis Log File:
    Logfile of HijackThis v1.97.7
    Scan saved at 10:24:30 AM, on 11/23/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\basfipm.exe
    C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\ChannelDeploy.sys
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Citrix\PNAgent\ssonsvr.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\System32\1XConfig.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\carpserv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Prism Deploy\Client\PTClient.exe
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Yahoo!\Messenger\ypager.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\Citrix\PNAgent\pnagent.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\Documents and Settings\ileanac\Local Settings\Temporary Internet Files\Content.IE5\0H6Z0DE7\HijackThis[1].exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://business.dellnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [bascstray] BascsTray.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [Prism Deploy Client] C:\Program Files\Prism Deploy\Client\PTClient.exe /Subscriber
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    O4 - HKLM\..\Run: [Trend OfficeScan ImageSetup] C:\Documents and Settings\Administrator\Local Settings\Temp\ImgSetup.exe /000f1fbce387
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] -HideWindow
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [MsnMsgr] C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\PTPNDFLS\PTPNDFLS.EXE
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\PNAgent\pnagent.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: http://*.citrite.net
    O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://hqtvcs01/OFFICESCAN/ClientInstall/WinNTChk.cab
    O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupIniCtrl Class) - http://hqtvcs01/OFFICESCAN/clientinstall/setupini.cab
    O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://hqtvcs01/OFFICESCAN/clientinstall/setup.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/yinst/yinst_current.cab
    O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwob.ops.placeware.com/etc/...uicksilver.cab
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...ntent/opuc.cab
    O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://hqtvcs01/OFFICESCAN/clientinstall/RemoveCtrl.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = citrite.net
    O17 - HKLM\Software\..\Telephony: DomainName = citrite.net
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = citrite.net

    Comment


    • #17
      Re: System32 Folder Opens at Startup

      Well guys! I figured it out! At least the system32 folder issue....still experiencing the other stuff...

      I downloaded EasyCleaner, which provides options for cleaning the registry, the add/remove programs, deleting unnecessary files and shortcuts, the startup programs, cookies, detects file duplicates, etc. You can download it here.

      Good luck!

      And if anyone has insight on the other issues...your help is very much appreciated!

      icastrillo

      Comment


      • #18
        Re: System32 Folder Opens at Startup

        Thanks guys. I registered to this site just to replay to you.

        I did all that Microsoft said but I didn't found any "" on the registry (and first I had to learn what the registry was and how to edit it) so I kept reading your notes guys and even though it didn't give me the full answer I found what cause it (on my case) and how to solve it.

        What cause it: Definitely it had to do with the Sound Blaster Audigy 2 sound card that I have in the computer. Looks like the bad "entry" was created at its installation and is bad or incomplete and looks for something that can be activated manually if needed.

        Bad line: /:ENG

        Where: Registry.
        at: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

        How to get it out:

        Go to the Start Menu, click on Run, enter "regedit", click OK, on the directory find HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run. It handles like any directory. Inside it you will see few entries and values.

        The one that you want to delete is: SB Audigy 2
        Startup /l:<?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /><st1:place w:st="on"><st1:country-region w:st="on">ENG.</st1:country-region></st1:place>

        Just delete that one and get out.

        There was a suggestion to go to MSCONFIG and deactivate the line on the
        startup menu but the order comes from the registry so if you take it completely out, you don't have to deactivate anything.

        Deactivating it on the
        startup menu is just a patch on a flat tire. Taking the line out is a tire that is never been flat.

        MSCONFIG is good though to find if you have that line on it.

        I don't remember all of it but the command reads as: /l:ENG and the location said: HKCU\Software\Microsoft\Windows\CurrentVersion\Run .


        I hope this helps somebody. It did it for mi.

        Thanks to all of you for your help .

        Alfonso == Telecom Manager
        Last edited by Telecom Manager; 11-25-2004, 04:38 AM. Reason: Typo & adds

        Comment


        • #19
          Re: System32 Folder Opens at Startup

          Another question guys:

          How do I create a new post?

          I looked everywhere and I can't find it!!!

          Thanks

          Comment


          • #20
            Re: System32 Folder Opens at Startup

            Originally posted by Telecom Manager
            Another question guys:

            How do I create a new post?

            I looked everywhere and I can't find it!!!
            At each forum category page are 2 New Thread buttons (left side near top and bottom).

            Comment


            • #21
              Re: System32 Folder Opens at Startup

              Would anyone mind taking a look at my HiJack log? I'd appreciate it.

              Thanks in advance.

              -Ed
              [email protected]

              Comment


              • #22
                Re: System32 Folder Opens at Startup

                For us to look at your hijackthis log you would need to post it. POst it in a new topic if you are having issues.

                Comment


                • #23
                  Re: System32 Folder Opens at Startup

                  Hey guys, I had the same system 32 problem and fixed it thanks to you all but a lil while ago, I had a problem when I dl'd msn plus. It gave me all this adware and I wanted to strangle the person that recommmended it to me but anyway, I got rid of the spyware but it did something to my computer where it would open up my aim folder...

                  C:\Documents and Settings\my name\Application Data\Aim

                  I tried deleting the registry :

                  HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\AIM

                  but all that didnt do anything but prevent my aim from starting when i open my computer and then reinstalled the registry when i would manually start up aim. It's doing the exact thing that the system 32 folder did in the past! arrrrghh! Yes I know I have a lot of im programs running but I can't help it lol all my friends can't unite to use one im. Becuz of my nooobality, I don't know how to retrieve my hijack log
                  Last edited by Bloodklot; 02-21-2005, 10:13 AM.

                  Comment


                  • #24
                    Re: System32 Folder Opens at Startup

                    Hi, I have been having this problem for a while now on my Dell Inspiron 8500 laptop. I tried searching for the L:\ENG with no luck

                    heres a link to my Hi-Jack This log, it wont let me post it because it says its too long


                    Last edited by ChrisDTC; 03-03-2005, 02:37 AM.

                    Comment


                    • #25
                      Re: System32 Folder Opens at Startup

                      Hi,

                      I got the same problem with System32 folder. I have tried the Microsoft fixed and uncheck all from startup (msconfig) but the issue remains.

                      Below is my hackthis log. Please! see if you can help me out. Thanks!

                      Logfile of HijackThis v1.99.1
                      Scan saved at 4:06:17 PM, on 6/13/2006
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\CTIServ.exe
                      C:\Program Files\Symantec AntiVirus\DefWatch.exe
                      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\Program Files\Symantec AntiVirus\SavRoam.exe
                      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                      C:\Program Files\UPHClean\uphclean.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\PROGRA~1\SYMANT~1\VPTray.exe
                      C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\censtat.exe
                      C:\Documents and Settings\linhsy\My Documents\hijackthis\HijackThis.exe
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.nvcc.edu/
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                      O4 - Global Startup: censtat.exe
                      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nvcc.edu
                      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nvcc.edu
                      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nvcc.edu
                      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                      O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
                      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                      O23 - Service: ctiserv - Centurion Technologies, Inc. - C:\WINDOWS\CTIServ.exe
                      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                      O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

                      Comment


                      • #26
                        Re: System32 Folder Opens at Startup

                        hey all, i have the same problem
                        here is my hijackthis log:

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                        C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
                        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                        C:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
                        C:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
                        C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
                        C:\WINDOWS\system32\RUNDLL32.EXE
                        C:\Program Files\iTunes\iTunes.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
                        C:\Program Files\MSN Messenger\MsnMsgr.Exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Google\Google Talk\googletalk.exe
                        C:\Program Files\AIM6\aim6.exe
                        C:\Program Files\AIM6\aolsoftware.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                        C:\Program Files\MSN Messenger\livecall.exe
                        C:\Program Files\Network Associates\VirusScan\mcshield.exe
                        C:\Program Files\MSN Messenger\usnsvc.exe
                        C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
                        C:\DOCUME~1\LOGANC~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
                        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                        O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
                        O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
                        O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
                        O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
                        O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Logan Carbin\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O11 - Options group: [INTERNATIONAL] International*
                        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.co...s/MsnPUpld.cab
                        O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                        O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} - C:\WINDOWS\system32\vpxnk.dll (file missing)
                        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                        O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
                        O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
                        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

                        anyone have anything? thanks

                        Comment


                        • #27
                          Re: System32 Folder Opens at Startup

                          Hi folks, Im having the same problem but it only happened after i did a destructive recovery of my HP machine (I do this periodically without ever having problems before).

                          Ive trawled through lots of posts for a solution but none seems to apply to me so hopefully my HijackThis log will help Thanks in advance for any help given.

                          Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                          Scan saved at 19:42:58, on 11/06/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\System32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                          C:\windows\system\hpsysdrv.exe
                          C:\HP\KBD\KBD.EXE
                          C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\WINDOWS\ALCXMNTR.EXE
                          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Documents and Settings\Owner\Desktop\HiJackThis_v2.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\00d78372e607669fc7230daeb58ad867\update\update. exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gb10.hpwis.com/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-gb10.hpwis.com/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-gb10.hpwis.com/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-gb10.hpwis.com/
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gb10.hpwis.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-gb10.hpwis.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-gb10.hpwis.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-gb10.hpwis.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://gb10.hpwis.com/
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                          O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                          O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [AutoTBar] Windows\services;C:\Program Files\ATI Technologies\ATI Control PanelAUTOTBAR.EXE
                          O4 - HKLM\..\Run: [adiras] adiras.exe
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
                          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1181512507312
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1181512482781
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{44BB2147-EED2-4E37-9EF4-64E0B89065C1}: NameServer = 212.139.132.6 212.139.132.7
                          O17 - HKLM\System\CS1\Services\Tcpip\..\{44BB2147-EED2-4E37-9EF4-64E0B89065C1}: NameServer = 212.139.132.6 212.139.132.7
                          O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
                          O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
                          O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                          --
                          End of file - 6314 bytes

                          Comment


                          • #28
                            Re: System32 Folder Opens at Startup

                            Hi guys, new here and I've been having the same issue of system32 folder opening on startup. Just need to know if anyone may have a little time to help. I guess I can start by d-loading hijack this and go from there. Anything to help as I've had it up to here that folder opening every logon. Plus it slows the process down. Thanks in advance

                            Comment

                            Working...
                            X