CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 952
Comments: 28
block bottom
spacer spacer

[DONE]HELP! Windows login logs right off again...

 
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
big_beach_bird

Cadet
Cadet


Joined: Jul 07, 2008
Posts: 3
Location: USA

PostPosted: Mon Jul 07, 2008 3:52 pm    Post subject: HELP! Windows login logs right off again...
Reply with quote

Yesterday when my daughter powered up a family computer she received an error message related to userinit.exe. She also received a message from Spybot's Teatimer asking her to allow or deny a registry change.

She (arrgghhh!) allowed the registry change and now our Windows user logins have been hijacked.

Apparently, from my research, this is because of an Ad-Aware removal of some portion of a Search Assistant/Blazefind thing and my userinit.exe has supposedly been replaced by wsaupdater.exe.

I tried microsoft's fix for the login problem which was to go into the Windows recovery console and "copy userinit.exe wsaupdater.exe".

This was SUPPOSED to restore my login capability from which I would be able to do a registry repair. I still cannot log on to windows from any of the user accounts, even in safe mode.

I would appreciate any advice you can give me. We just loaded a lot of the family photos (college graduation) into this computer and had not yet had a chance to burn them to CD, we are pretty scared!

Back to top
View users profile Send private message
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3683
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Tue Jul 08, 2008 8:23 am    Post subject:
Reply with quote

Hello

I have asked for the thread to be moved to HJT forum where one of the trained helpers will be able to advise on the next course of action

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Jul 08, 2008 1:34 pm    Post subject:
Reply with quote

I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note to everyone: You must be a CastleCops member to post for help in the HJT forum. Do not post a HJT log anywhere other than in our HJT forum. If you post them here or in other forums, they will be deleted or ignored.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
big_beach_bird

Cadet
Cadet


Joined: Jul 07, 2008
Posts: 3
Location: USA

PostPosted: Wed Jul 09, 2008 2:56 pm    Post subject:
Reply with quote

Thanks for your reply, PCBruiser.

I tried the "wiki" link, it won't load from your link OR from the side-bar link.

I have read the HJT guidelines, have no p2p software but cannot run HJT because I cannot get into windows. For the same reason, I cannot run any other malware cleaners, online scanners, etc.

If I could get past the login problem, I would have no problem cleaning up my registry, etc. I have successfully cleaned other machines without help.

It's sounding more and more like I just need to nuke my drive and re-pave it. Took the hard drive and attached it to another machine, I'm pulling off the files that mean anything and just going to re-load Windows.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can report post to moderators in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer