
Re: Re: Logon - logoff loop
Quote:
Originally posted by splashy
Well it looks nice, but there is NO WAY I can change anything on the
harddrive because after logon is a logoff,
also in savemode you cannot intercept, it just keeps on going to logon.
The computer has a up to date (16 dec) virusscanner and firewall, ad-aware
and hyjack this.
Help is badly needed ;) Rolphe
|
Hi there,
my solution to your problem:
I used a boot CD made with Barts PE Builder (http://nu2.nu/pebuilder/) from my WIN XP Prof Installation CD with soem extra tools:
The McAffee Command line Scanner and the Registry Editor from J. Mazlovsky mentioned on Barts PE site.
Also the Total Commander as "Explorer".
- Boot from CD
- Start a Virus Scan with McAffee and clean found files
- Start Registry editor and load the ntuser.dat out of your Profile.
- Look for the key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\Cu rrentVersion\Winlogon and correct it like Ronaldo did.
In my case, McAffee found the adclicker.AU virus in several files named
- C:\WINDOWS\system32\iProtect.exe
- C:\WINDOWS\system32\axe.exe
- C:\WINDOWS\system32\winsecure.exe
- C:\WINDOWS\system32\memorymanager.pif
- C:\WINDOWS\system32\ins32.dll
- C:\spooler.exe
- C:\WINDOWS\msupdate.exe
- C:\cab.exe
It even changed the "hosts" file in - C:\WINDOWS\system32\drivers\etc
The Virus was originally located in an executable ebook , which has been scanned with AntiVirPE (UptoDate Vir.def of course) and NO Virus was detected!!!
Changing the userinit part without removing the infected files had the same effect Roberto got.
Quote:
After login and log off the problem went back
Find out that the file c:\winsecure.exe was changing the registry,
Some kind of malware, I think...
deleted file and found in the registry the following line:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
Name: Windows Security Manager value: c:\winsecure.exe
|
ATTENTION: Please look for the correct Windows-PATH (e.g. C:\WINDOWS or C:\WINNT or maybe your own choice), I got it wrong and the System hung in the logn loggoff loop again!
Greetz, Joe