I have no entry in the startup of MSCONFIG that looks like this... Deselect /L:ENG entry from the startup tab
Main Topics
Browse All TopicsOne of my XP systems is now opening the "system32" folder each time someone logs into the local computer. I have checked for virus infection, ran spybot and adaware, and ran hijackThis on it but cannot figure out what is causing this. I have also tried the #260 tip listed in other threads but that runs and says there is no entry of that type in registry. I have checked the registry RUN commands but have no strange entries there. I have disabled everything in the MSCONFIG startup items and that does not help either.
Here is the info I copied from HijackThis...
StartupList report, 6/22/2006, 2:43:01 PM
StartupList version: 1.52.2
Started from : C:\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==========================
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\PROGRA~1\Grisoft\AVGFRE
C:\PROGRA~1\Grisoft\AVGFRE
C:\WINDOWS\system32\cisvc.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\cidaem
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE
C:\WINDOWS\system32\ctfmon
C:\HijackThis.exe
--------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
UserInit = C:\WINDOWS\system32\userin
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
(Default) =
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ctfmon.exe = C:\WINDOWS\system32\ctfmon
--------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\Sy
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\SPYBOT~1\SDHel
--------------------------
Enumerating Task Scheduler jobs:
Norton Internet Security.job
Symantec NetDetect.job
--------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macrom
CODEBASE = http://fpdownload.macromed
--------------------------
Enumerating ShellServiceObjectDelayLoa
PostBootReminder: C:\WINDOWS\system32\SHELL3
CDBurn: C:\WINDOWS\system32\SHELL3
WebCheck: *Registry key not found*
SysTray: C:\WINDOWS\System32\stobje
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
wininet.dll =
kernel32.dll = C:\WINDOWS\system32\
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
This problem has been addressed many times on this site:
http://search.experts-exch
What you posted is the Hijackthis' generated startup list not the real Hijackthis log.
Can we look at the proper hijackthis log please?
Post the log at either of these sites:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:
Or paste the log at --> http://www.hijackthis.de/
and click "Analyse", click "Save". Then post the link to the saved list here.
Also, Can we look at the all the "Run" keys?
Could be something to do with this entry below:
>>>HKLM\Software\Microsoft
kernel32.dll = C:\WINDOWS\system32\<<<
--------------------------
cd\WINDOWS\desktop
regedit /e /a HKCURun.txt "HKEY_CURRENT_USER\Softwar
regedit /e /a HKLMRun.txt "HKEY_LOCAL_MACHINE\Softwa
Copy and paste the aboved text into Notepad.
Save this text as "Log.bat" Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
Double-click on the "Log.bat" after it flashes, 2 txt files are created on your desktop, HKCURun.txt and HKLMRun.txt
Post the contents of the txt files.
Thanks rpggamergirl! Below is your last request. I will get back to you soon with the hijack log requested.
HKCURun.txt
REGEDIT4
[HKEY_CURRENT_USER\Softwar
"ctfmon.exe"="C:\\WINDOWS\
--------------------------
HKLMRun.txt
REGEDIT4
[HKEY_LOCAL_MACHINE\Softwa
"AVG7_CC"="C:\\PROGRA~1\\G
[HKEY_LOCAL_MACHINE\Softwa
[HKEY_LOCAL_MACHINE\Softwa
"Installed"="1"
[HKEY_LOCAL_MACHINE\Softwa
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\Softwa
"Installed"="1"
ok, here is the link to the hijackthis log...
http://www.rafb.net/paste/
Sorry the run keys didn't help and your Hijackthis log didn't help either, not much to tell there.
Can you please Export this Run key to your desktop(as a regfile) and post the contents of the reg file here? that might tell us something, otherwise I'm out of ideas.
HKLM\Software\Microsoft\Wi
Can you also check this registry key:
HKEY_LOCAL_MACHINE\SOFTWAR
then on the right pane, look for the "userinit" and make sure there is no other data but this --> C:\Windows\System32\Userin
there should be no other data but --> C:\Windows\System32\Userin
You can manually delete the "kernel32dll" value or use this regfile below.
Make sure the key you exported before stays in your desktop because that is your backup.
Copy and paste the bolded text into Notepad.
Save this text as "Deleteme.reg" Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
Double-click on the Deleteme.reg and when it asks you to merge the information to the registry click Yes. (delete the reg file you created on your desktop after the successful merged)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWA
"kernel32.dll"=-
Business Accounts
Answer for Membership
by: JoeZ430Posted on 2006-06-22 at 12:57:22ID: 16963453
Maybe this will help you.
e.com/Oper ating_Syst ems/WinXP/ Q_21056081 .html?quer y=SYSTEM32 +folder+op ens+on+sta rtup& clear TAFilter=t rue
http://www.experts-exchang