Stuck at System 32

Discussion in 'Software' started by MacKay73, Dec 13, 2013.

  1. MacKay73

    MacKay73 Private E-2

    Hi

    Our Dell family laptop has either got a bug or some kind of software/hardware failure.

    Two days ago when it booted up it got to the desktop screen and then started to freeze with the icon beach balling.

    After a few restart attempts it is now stuck on a black screen with a cmd.exe mini screen with the C:\Windows\system32> up. This is the same on each reboot.

    We have downloaded the programmes recommended Roguekiller etc but don't know how to run these from the screen we are at. Can anyone help?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have moved your thread to software. As soon as you are back up and running you can pop over to malware removal again. :)
     
  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Is the normal desktop showing behind the mini screen?

    What model Dell?

    Have you tried tapping F8 at startup? What happens when you try to boot into safe mode, last know good configuration?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And another question to answer is, "What version of Windows is being used"? ;)
     
  5. MacKay73

    MacKay73 Private E-2

    It's a Dell Xpsl502x

    Windows7

    The screen behind the cmd.exe box is completely black.
     
  6. MacKay73

    MacKay73 Private E-2

    F8 brings Windows Error Recovery up but options I have tried lead back to the same screen. Good chance I am choosing the wrong option however.
     
  7. MacKay73

    MacKay73 Private E-2

    Instead of the completely black screen it has safe mode in each corner when using F8
     
  8. rustysavage

    rustysavage Sergeant Major

    Do you have any sort of boot disk available, like a program rescue disk or a Windows 7 repair disk? Windows Installation disks?

    If you are posting messages from a computer that's running Windows 7 you can make a Repair Disk using the optical drive of the computer you are posting from (assuming that the computer you're on has an optical drive). If the laptop has no CD/DVD drive then the repair disk won't help you in this instance but it's always good to have one handy, so go ahead and make one regardless.

    http://windows.microsoft.com/en-us/windows7/create-a-system-repair-disc

    If both computers have an optical drive and you were able to create a Repair Disk, then pop it into the laptop's CD/DVD drive and reboot the broken computer. That should boot up to the Windows Repair environment.
     
  9. rjordan

    rjordan Private First Class

    Sounds like a hung registry entry.

    Type start explorer.exe
    Does your desktop appear?

    Type start regedit.exe
    Does it open the Registry Editor?

    Type tasklist
    List off the names please (don't need the full info)
     
  10. MacKay73

    MacKay73 Private E-2

    Desktop does appear and I can get Registry Editor. When I type tasklist a box springs up data zooms down and the box instantly disappears.
     
  11. MacKay73

    MacKay73 Private E-2

    I unfortunately don't have a repair disk to hand.

     
  12. rjordan

    rjordan Private First Class

    Registry Editor opens correct?

    ****DO NOT MAKE ANY CHANGES SIMPLY REPORT****


    Navigate to the following keys and tell me what is in there.
    If you find any values that are weird looking or have a long file path, feel free to mention them

    HK_Local_Machine\Software\Microsoft\Windows NT\Current Version\Winlogon\

    Looking Under "Shell", should only have explorer.exe in the value

    Userinit, post the entire string

    HK_Current_User\Software\Microsoft\Windows NT\Current Version\Winlogon\

    Looking Under "Shell", should only have explorer.exe in the value
    (If you see no "shell" value here, this is fine)

    Userinit, post the entire string
    (If you see none, this is fine)


    HK_Classes_Root\CLSID\{fbeba05-(forgot the rest)\Parameters\
    The key value listed there should say "%Systemroot%\system32\shell32.dll" if it does not have that, post what it says



    EDIT - I just re-read and saw that your desktop does appear now. You can skip the step I posted above and proceed with normal Malware removal steps, your choice.
     
  13. MacKay73

    MacKay73 Private E-2

    Shell only has explorer.exe
    Userinit C:\Windows\system32\userinit.exe,

    No Shell and no Userinit in the second one.

    No HK_Classes_Root\CLSID\{fbeba05 file path

    But I have ran the scans and will attach in next message.
     
  14. MacKay73

    MacKay73 Private E-2

    Attached are the logs requested in Malware scans.

    Thanks for the continued assistance.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well malware scan logs really belonged in the Malware Forum, but since this thread was moved from the Malware Forum to here let's just answer here in the Software Forum. Your logs do not show any malware problems so if you are still having problems, you are in the correct forum. And since your logs are from normal boot mode, I would have to ask exactly what problems are you trying to fix.
     
  16. MacKay73

    MacKay73 Private E-2

    The no malware is good news but I still switch on and after I log on I get the black desktop screen with the cmd.exe black panel with C:\Windows\system32>

    The way I have been getting to the desktop is to type explorer.exe. Once there all basics like sound, internet, avg, Intel turbo boost technology are not working.

    I hope to source a windows 7 disk soon. This all started when my desktop started to freeze minutes after logging in.
     
  17. rustysavage

    rustysavage Sergeant Major

    Not sure exactly what you mean by "source a windows 7 disk" but if it's an installation disk you're after and you own a legal copy of Windows 7 then you can download a Windows 7 (32-bit & 64-bit) ISO file that you can burn to DVD and use legally by entering your own Microsoft Windows 7 product key:

    http://www.askvg.com/direct-downloa...nd-untouched-windows-7-iso-32-bit-and-64-bit/

    Here's the disclaimer from the site:

    "DISCLAIMER: The download links given in this topic are genuine and absolutely legal. You should have a valid product key with you to be able to install Windows 7 using these ISO files. If you don't enter a product key, Windows will run only for 30 days.

    When we purchase a new computer, it comes pre-installed with an OS, most of the times the OS is Microsoft Windows. Now almost all new computer systems are coming pre-installed with Windows 7.

    Some computer manufacturers provide a recovery disc with their computers so that you can restore the OS in case you face problems while starting Windows.

    But what would you do if you didn't get the recovery disc or if you lost the recovery disc. Even if you have your genuine product key noted down in your diary or printed on the backside of your computer, you can't use it to reinstall Windows because you don't have the setup disc.

    To solve your problem, we are going to list direct download links for Windows 7. These are genuine and official download links. Its completely LEGAL to use them as they are hosted by "Digital River" online store which is an official distribution partner of Microsoft. These ISO files don't come with a product key. You'll need to use your own product key to activate Windows. The links provide an untouched Windows 7 ISO which is a fully functional 30-day trial version which can be converted into full version after entering your product key and activating it."

    Here' the file list of what can be downloaded from this site:

    Download Windows 7 Professional with Service Pack 1 (SP1):

    English 32-bit
    English 64-bit
    Chinese 32-bit
    Chinese 64-bit
    Danish 32-bit
    Danish 64-bit
    Dutch 32-bit
    Dutch 64-bit
    Finnish 32-bit
    Finnish 64-bit
    French 32-bit
    French 64-bit
    German 32-bit
    German 64-bit
    Italian 32-bit
    Italian 64-bit
    Korean 32-bit
    Korean 64-bit
    Norwegian 32-bit
    Norwegian 64-bit
    Portuguese 32-bit
    Portuguese 64-bit
    Spanish 32-bit
    Spanish 64-bit
    Swedish 32-bit
    Swedish 64-bit

    Download Windows 7 Home Premium with Service Pack 1 (SP1):

    English 32-bit
    English 64-bit
    French 32-bit
    French 64-bit
    Spanish 32-bit
    Spanish 64-bit

    Download Windows 7 Ultimate with Service Pack 1 (SP1):

    English 32-bit
    English 64-bit
    French 32-bit
    French 64-bit
    Spanish 32-bit
    Spanish 64-bit

    Download Windows 7 Professional RTM without SP1:

    English 32-bit
    English 64-bit
    Chinese 32-bit
    Chinese 64-bit
    Danish 32-bit
    Danish 64-bit
    Dutch 32-bit
    Dutch 64-bit
    Finnish 32-bit
    Finnish 64-bit
    French 32-bit
    French 64-bit
    German 32-bit
    German 64-bit
    Italian 32-bit
    Italian 64-bit
    Korean 32-bit
    Korean 64-bit
    Norwegian 32-bit
    Norwegian 64-bit
    Portuguese 32-bit
    Portuguese 64-bit
    Spanish 32-bit
    Spanish 64-bit
    Swedish 32-bit
    Swedish 64-bit

    Download Windows 7 Home Premium RTM without SP1:

    English 32-bit
    English 64-bit
    German 32-bit
    German 64-bit
    French 32-bit
    French 64-bit
    Spanish 32-bit
    Spanish 64-bit

    I've downloaded a copy, burned it, and used it successfully, so it's legit. Hope that helps.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before working on anything from rustysavage's reply, please see my comments/instructions below.

    I would say this is because many of your Windows services are not running. Try doing the below.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).



    Then attach the below log so I can see the effect:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    Note that you are using the USERPROFILE=C:\Users\Alan H and this user profile is a member of the administrator group. You have no password setup on this user account. This is a very very bad idea! If you did get malware, it would have full ability to do anything it wants because you have no password setup. In fact malware could put in a passord and block you from logging into your own PC.
     
    Last edited: Jan 3, 2014
  19. MacKay73

    MacKay73 Private E-2

    Thanks to you both. I will try the latter suggestion first and see how I get on but i have the product key and will definitely do the former also for any future difficulties.

    I will let you know how I get on.
     
  20. MacKay73

    MacKay73 Private E-2

    I have run Windows Repair - it didn't take that long to complete. Unfortunately there does not seem to be any change after running the repair.

    Attached is the requested log and I have also attached a picture of what the desktop screen looks like after logging in.

    I have also deleted the user account with no password.
     

    Attached Files:

  21. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Type explorer after what is in the cmd window.
    When windows loads, look for the following keys (run regedit)
    1. HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon
    look for a shell key with a value of cmd.exe and delete it.
    2. HKEY_CURRENT_USER\Software\Microsoft\Command Processor
    look for an autorun key with cmd.exe and delete it.
     
  22. MacKay73

    MacKay73 Private E-2

    plodr: I checked both those keys and could see neither - I have attached pictures of what was in both just to be sure. Not sure where to go next....

    Rustysavage: I have also downloaded the ISO. When I run the burned CD it comes up with Install Now. Is this a complete reinstall?
     

    Attached Files:

  23. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    The screenshots were helpful.
    On my current XP desktop computer, I do not have First Logon and in the second sceenshot, I do not have Path Completion Char .

    I'm now going to look at the other XP computers in the house then I'll search to see what these do.

    ooops, I see you are running Win 7. Back to the drawing board. Give me some time to see if what I posted above in regards to the registry keys was for XP or 7. :-o
     
  24. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    This is for Win 7 and I checked on one of the Win 7 computers in the house.
    Check
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

    There will be a lot of entries in the right pane. Scroll down until you see Shell. Make sure the Data is explorer.exe
    You can double-click Shell and a box will popup; from there you can edit the data value to explorer.exe
     
  25. MacKay73

    MacKay73 Private E-2

    The data is currently explorer.exe in that path.
     
  26. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Okay, I only have two more thing you can try. If they don't work, I'm out of ideas.

    1. In the run box, after windows is loaded type in
    Code:
    msconfig
    and press enter.
    Click on the Startup tab. Look over the contents. Do you see cmd.exe anywhere? It might be disguised as something else.
    You want to do two things: uncheck it and also expand the Location box until you can see the full path. Write down this path so you can go into the registry later and nuke it.


    2. Download Autoruns. http://www.majorgeeks.com/files/details/microsoft_autoruns.html
    It is an exe so there is nothing to install; you might have to unzip it before you see the exe file to click on. There might also be two exe files. Click on the autoruns not the autorunsc.
    Screenshot http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

    Stay on the everything tab.
    Scroll down and see if cmd.exe is listed anywhere. If it is, the location/full path will be highlighted in blue above it. Write the path down so you can go to that registry key and nuke it.
     
  27. MacKay73

    MacKay73 Private E-2

    There is a system32\hkcmd.exe in one of 3 Intel Common User Interface startup items. ??
     
  28. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

  29. rjordan

    rjordan Private First Class

    There is way too many things that need to be checked in a time like this.

    Walking through these steps over forums is a bit tedious at best.


    If the PC has an internet connection and if you are willing, I will offer to do a remote desktop connection sometime and take a look.
    All of my expierence comes from remoting to PC's and troubleshooting from there.

    Up to you
     
  30. MacKay73

    MacKay73 Private E-2

    Plodr: No sign of it that I can see in autoruns and checked entry and image paths five times.

    I don't have much stored in the laptop so getting to the stage of accepting a complete reinstall might be the best option.
     
  31. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Sometimes a re-install is the best option.

    I might suggest learning how to make images of the laptop. I image our computers about every two months. (I should do it more often but with so many computers in the house, I simply do not have the time). If something acts up, you restore the image then only have to do a month or two of updates rather than several year's worth.
     
  32. rustysavage

    rustysavage Sergeant Major

    Allow me to second that suggestion (and third and fourth it as well).
    Here are a few suggestions for backup programs that do disk imaging:

    AOMEI Backupper (freeware) http://www.backup-utility.com
    Macrium Reflect (freeware) http://www.majorgeeks.com/files/details/macrium_reflect_free_edition.html
    Paragon Drive Backup (freeware) http://www.majorgeeks.com/files/details/paragon_drive_backup.html
    O&O DiskImage Express (freeware) http://www.majorgeeks.com/files/details/oo_diskimage_express.html
    EaseUS ToDo Backup (freeware) http://www.majorgeeks.com/files/details/easeus_todo_backup_free_edition.html
    Acronis TrueImage (shareware) http://www.majorgeeks.com/files/details/acronis_true_image_home_2013.html
    NovaStor NovaBACKUP (shareware) http://www.majorgeeks.com/files/details/novabackup.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds