I encountered another computer in less than a week with the same problem. The computer would log in and rapidly log off mere seconds from each other. I check the usual suspects, spyware and malware. Nothing.
I then suspect it is a userinit missing issue. (userinit loads explorer.exe which loads one's background and icons etc)
I searched the c:\windows\system32 folder. There is a perfectly good copy.
My only other suspicion is that the registry key that points to the userint.exe file is pointing to the wrong or is pointing to a dubious location.
The winlogon key under the hklm hive contains the pointer for the userinit.exe file.
I was wrong again. The pointer wasn't wrong or pointing to a non existent location. It was blank. Curiously, the the pointer field was empty. I inserted the proper pointer field.
c:\windows\system32\userinit.exe,
I booted the pc. The username logged in with no problems. Immediately after logging in, Microsoft's malicious software removal tool or MRT, popped up that it had successfully removed a piece of malware. I would bet money that the MRT removed the key in question as lot of malware try to manipulate the userinit.exe file to ensure that thier payload is executed when the user logs in. I blame the computer not logging in on Microsoft. The removal tool was a little over zealous. Anyone know for sure?
Showing posts with label Spyware Removal. Show all posts
Showing posts with label Spyware Removal. Show all posts
Monday, April 20, 2009
Tuesday, April 14, 2009
Windows XP computer logs on and instantly off
I had dell computer I had to fix. It turns out that the userinit.exe file was missing from the c:\windows\system32\ folder.
Of course, it was the last thing I checked. I removed all the win antispyware 2009 garbage files and checked the registy to make the winlogon key pointed to userinit.exe. I searched the hard drive for any copies of userinit.exe. I found 2. The most recent file came from the c:\windows\servicepackfiles\i386 folder. It looks like the customer tried to remove the spyware using anti spyware software and it ate the userinit.exe file. After I replaced the file, the computer logged in without any problems. I hope this helps someone else.
Of course, it was the last thing I checked. I removed all the win antispyware 2009 garbage files and checked the registy to make the winlogon key pointed to userinit.exe. I searched the hard drive for any copies of userinit.exe. I found 2. The most recent file came from the c:\windows\servicepackfiles\i386 folder. It looks like the customer tried to remove the spyware using anti spyware software and it ate the userinit.exe file. After I replaced the file, the computer logged in without any problems. I hope this helps someone else.
Saturday, April 11, 2009
User32.dll bad image or checksum
I had a customer drop off a dell laptop that would blue screen before the windows xp logon screen comes up. It looks like the customer tried to use combofix and other antispyware tools to remove spyware on the machine.
I hate fixing a computer that has been "fixed" already. It makes it harder to define the problem as weird variables crop up. I got relatively lucky. I found a recent copy of the user32.dll file in the c:\windows\servicepackfiles folder and replaced the current user32.dll. The bad user32.dll file had a modified date of today. The replacement user32.dll file had a modified date of 2 weeks ago.
Before I restarted the computer, I manually removed the spyware and rootkits. Magically, the pc fired right up.
I feel sorry for the new computer guys out there as the spyware out there now is pretty tough. I do not think this computer would have been fixed if I had to rely on anti virus software to clean the pc.
I hate fixing a computer that has been "fixed" already. It makes it harder to define the problem as weird variables crop up. I got relatively lucky. I found a recent copy of the user32.dll file in the c:\windows\servicepackfiles folder and replaced the current user32.dll. The bad user32.dll file had a modified date of today. The replacement user32.dll file had a modified date of 2 weeks ago.
Before I restarted the computer, I manually removed the spyware and rootkits. Magically, the pc fired right up.
I feel sorry for the new computer guys out there as the spyware out there now is pretty tough. I do not think this computer would have been fixed if I had to rely on anti virus software to clean the pc.
Subscribe to:
Posts (Atom)