SYSTEM32 Folder on Startup/Windows STANDBY Failure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TS26720, Oct 21, 2006.

  1. TS26720

    TS26720 Private E-2

    I Have 2 problems.

    1) When the computer boots up I get SYSTEM32 Folder. I have run the removal tooll in Kelly-Korner and did not work. I have followed tthe hreads on you site and cound not find the problem. I have booted computer in Selective start with startup files disabled and still have the problem. I have attached the HIJACK file and hope you can see the issue.

    2) The computer will not enter standby mode. I get an error message "System Standby Failed - The device drivre for the easy internet keyboard device is preventing the machine from entering standby .....". I have a VPR Matrix Desktop computer with logitec corded deluxe access keyboard. The keybooard used itouch software. I have tried the latest itouch software and I have tried the itouchsoftware that came on the device driver disk with the computer. I have tried removing all the itouch software and using a basic PS/2 Keyboard and driver with similar failure message. No Sucess yet.

    I did use the READ AND RUN me first link on you site and removed some MALWARE. I have attached the HIJACK log, ActiveScan.txt and bdscan.txt files.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi could you also attach the ShowNew and GetRunKeys logs as listed in the guide as well... cheers.
     
  3. TS26720

    TS26720 Private E-2

    Attached are the runkeys.txt and newfiles.txt files. Thanks very much for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Neither of your problems are really malware issues.

    The first problem typically occurs due to a null type entry in one of the registry keys used to load startup items. However, a quicklook at your logs does not reveal a problem like this. Did you attach logs for the user account that is displaying the problem?

    The second problems you mention is an issue you should be discussing in the Hardware (maybe Software) Forum.

    Let's address a few non-malware issues and see what happens.

    Is your copy of CA eTrust PestPatrol a paid version or a free trial? If free uninstall it.
    Is you copy of Spy Sweeper for MSN a fully functional program that provides active blocking as well as scanning features?

    You must not have PestPatrol, Spy Sweeper and Windows Defender all install. Are goal will be to keep only one and preferably one that is paid program and that is fully functional.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    After clicking Fix, exit HJT.[/COLOR]

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. HJT


    Make sure you tell me how things are working now!
     
  5. TS26720

    TS26720 Private E-2

    In the original post I created the bdscan and Activescan txt files when in Safe Mode and I believe I was in administrator mode. The HJT, Getrunkey and newfiles were created in the normal account with the problems. When I boot up in SAFE mode I do not have the SYSTEM32 folder pop up.

    I created a new account and logged in to find it had the exact same problems. I deleted the account again.

    I deleted Pest Patrol and MSN Spy Sweeper which are expired subscriptions. I left Defender alone but I don't believe it runs in startup for constant protection.

    Hidden files are enabled.

    I fixed the lines you said using HJT. Note the log file was made before I deleted the lines.

    When I selected Reset Web Settings I was asked if I wanted to reset to the default settings. I said no.

    I ran fixWLK.reg and merged the new code into the registry file.

    I have attached new logs for HJT and Getrunkey.

    The computer has the same problems as before with no new problems noted following these changes.

    What do you recommend I try next? Thanks for the help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow directions in the order given. I don't need a log that still shows me what I was asking you to fix.

    Why did you say no? My instructions said we are doing a Reset Web Settings, you need to allow the reset to work otherwise you are not resetting the web settings as I requested. Please do this again and say yes!

    Now that you uninstalled Spy Sweeper you need to have HJT fix the below left over from it:
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Then attach a new HJT log from normal boot mode.

    Is the user account that appears to be having the problem named FAMILY
    If so, does this account have Administrator priviledges?

    If not, give it Administrator priviledges and then reboot into safe mode and login to the FAMILY account. Safe a HijackThis log from safe mode and also note whether the system32 folder opened in safe mode.

    Then reboot in normal mode and attach this second log which is from safe boot mode.
     
    Last edited: Oct 25, 2006
  7. TS26720

    TS26720 Private E-2

    I reset the Web Settings to the original default settings and then reset the home page on the General Tab to www.majorgeeks.com. Note I deleted the Cookies and the fiels , however I do not appear to have an option to Delete all offline content.

    I fixed the O20 line you identified and ran a HJT log from Normal Boot mode. The log is called highjackthisc.log

    The Family account has administrator privalages. I booted up in Safe mode and logged in as FAMILY. I did not get a SYSTEM32 folder pop up. I have attached the HJT file which I ran in Safe mode. It is called hijackthisd.log.

    I guess the clue to this problem should lie in the difference between these log files.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you click the button to Delete Files... the next window that pops up is titles Delete Files. In this window there is a check box to Delete all offline content and there are two buttons OK and Cancel. Select the check box and click OK!


    I don't see an obvious reason for this to be occurring there are no null entries showing in the run keys which can typically cause this. Either way it is not an issue for this forum since it is not malware. You should try the Software Forum. I will give you the below information though which is a list of what addition processes are running in normal boot mode versus safe mode. Some of them load thru normal startups (the O4 lines seen in HJT and also seen under the Startup tab of MSconfig) and other load because they are Services but certain services will only load in normal boot mode. You can also see a Services tab in MSconfig. Using the Startup tab and Services tab you can experiment with the items that are in the difference list (the diff between your safe mode and normal mode logs) below. You can stop various ones from loading to see if any of them are causing this. I tend to doubt they are the cause but they could be.

    HERE ARE THE DIFFERENCES:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds