need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by dromano, Jun 5, 2007.

  1. dromano

    dromano Staff Sergeant

    Hi All,
    A friend brought her comp over to see if i could get the Famous Major Geeks to give us a hand trying to get her going again. She has a Compaq Presario x1000 running XP and IE6. I believe she has some major malware and virus problems. We can not get it to run at all every time i click a user name it says it is loading personal settings then goes to the screen loading windows XP and back to click on a user name. I tried to do the read and run me first but can't log on in normal mode. PLEASE ADVISE us as to where to go from here.confused:cry
    Any and all help would be great!
    Thanks in advance,
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are potentially in the wrong forum. This sounds typical of what happens when the userinit.exe file is either deleted or the registry key used for loading it has been deleted or incorrectly edited. Does the same thing happen in safe boot mode? Can any other user accounts be logged into?

    You should continue working this in the Software Forum. You will more than like need your friends Windows XP boot CD. If you don't have a boot CD, you are in trouble.

    Often a procedure as documented in the below link is required:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  3. dromano

    dromano Staff Sergeant

    Thanks Chaslang,
    When i tried to boot up this am it worked but all sites came up as restricted and then the comp froze up. When i tried to boot again i recieved (B1 Stack Server.exe license invalid) There is one other user and the same problem. Upon another try at booting it was back to the same booting over and over again. In safe mode the same thing happens but once in a while it will start up and then freeze. I will post in software as suggested. Thank you for the advise and your time.
    Dan
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you can get it to boot up again, do the below.

    Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools While these tools will run from your Desktop, we strongly recommend that you DO NOT extract them to your Desktop. Please install them where recommended.
    • Locate the getrunkey.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) DO NOT attach any other file. The log is named runkeys.txt. We do not need any of the other 20 or so temp files that are created. They will all be deleted when you terminate GetRunKey by closing the notepad window. This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment when you come back to post your results.
    • Please make sure you close the popup notepad window with the runkeys.txt log in it before running ShowNew in the below step.
    • Locate the shownew.bat file and double click on it to run it. It will create a file named newfiles.txt in the root of drive C: (C:\newfiles.txt) . This log will also popup in a notepad window which your can just close. Upload the newfiles.txt file here as an attachment when you come back to post your results.
    Then see step 7 in this READ & RUN ME FIRST Before Asking for Support and attach a HijackThis log.



    Note: This means I expect to see three logs attached. See: HOW TO: Attach Items To Your Post

    • GetRunKey
    • ShowNew
    • HJT
     
  5. dromano

    dromano Staff Sergeant

    Hi Chaslang,
    Thank you for the all the help! I hope i did it all right attached are the three logs as requested.
    Thank you,
    Dan
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well based on those logs I do not see any malware. You will have to run the real antivirus and antispyware scanners requested in the READ ME to know for sure if you are clean. GetRunKey, ShowNew and HJT are not malware scanners so there could be things detected by the other tools. However, I do suspect that your problems (whatever they are) are not due to malware. Consider running the other tools but if they do not detect anything, you should post in the Software Forum.
     
  7. dromano

    dromano Staff Sergeant

    Hi Chaslang,
    As insane as it sounds the comp has been booting up fine since yesterday. I found no viruses spybot found 34 threats and fixed them and all seems to be well. Thank very much you for your help. I don't know what fixed it or how but I'll not be questioning the results.confused:Dconfused:D
    Thanks again,:wave
    Dan
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's great and you're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    3. After doing the above, you should work thru the below link:
     
  9. dromano

    dromano Staff Sergeant

    Hi Chaslang,
    Done as ordered and thanks again.
    Dan
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds