Wierd login issue

Discussion in 'Software' started by Olomion, Apr 7, 2009.

  1. Olomion

    Olomion Private E-2

    I have a friends computer that began behaving in a way I have never seen. It's further complicated because the friend never created their recovery disk set... I may have to order them if possible from Dell but I'd prefer to find a way to fix the problem.

    In short, any log on attempt appears to be loading Windows XP Media Edition and then immediately displays a dialog box titled "FIXED" with the only text in the dialog box being "Fixed" and upon pressing the "OK" button you are returned to the User account screen...

    Likely a viral infection of some kind... but has anyone seen this or have more info on whats causing it?

    Thanks in advance!
     
  2. Cordialis

    Cordialis MajorGeek

    Try Safe mode: what you do is that you reboot. And right away you start tapping on the F8 key - from the second you hear the PC waking up again. You want to see white text on a black background. Then use the arrows on your keyboard to get to safe mode with network.

    Microsoft articles about "Safe Mode": http://windowshelp.microsoft.com/Windows/en-US/help/323ef48f-7b93-4079-a48a-5c58eec904a11033.mspx
    http://support.microsoft.com/kb/315222/en-us

    Run some full scannings in safe mode. Install, update and run these:

    MBAM: http://majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
    SAS: http://majorgeeks.com/SUPERAntiSpyware_d5116.html[/QUOTE]

    Finally run chkdsk. Article: http://support.microsoft.com/kb/315265/en-us
     
  3. Olomion

    Olomion Private E-2

    My first attempt was in safe mode... even safe mode (command prompt) behaves the same way. Without safe mode it tries to boot into one users account and then does the same thing and upon clicking ok it just goes to the User accounts screen.

    I think it's a rebuild situation in truth... I'd just like to know what little bugger is doing it...
     
  4. hrlow2

    hrlow2 MajorGeek

    Did the machine have Media Edition installed, or did someone try to repair it with a Media disk?
     
  5. the mekanic

    the mekanic Major Mekanical Geek

    If you haven't posted in the Malware section of the forum, please do so. They can come up with a better solution, as they are professionals, and damn good at what they do.
     
  6. Cordialis

    Cordialis MajorGeek

    Well, then we have some of those BIOS things. We'll have to wait for others to enter the thread because I don't have that stuff under my belt...

    Edit: some fine folks just did! :cool Here's the guide to malware removal even though you can't follow it: http://forums.majorgeeks.com/showthread.php?t=35407
     
  7. Olomion

    Olomion Private E-2

    It Came shipped with Media Edition... Dell Dimension E310 Windows XP Media Edition.

    I got into it with a knoppix cd and don't see anything real nasty (and I am used to cleaning up people's messes...) I fear something has infected the login dll's
     
  8. Olomion

    Olomion Private E-2

    Oh... and I can restore from the hidden partition... but I hate to lose all their data... ouch...
     
  9. Cordialis

    Cordialis MajorGeek

    Upload all their data, docs, pics etc. to some online store place. Just open an account somewhere. Here's Windows Live SkyDrive: http://skydrive.live.com/
     
    Last edited: Apr 7, 2009
  10. the mekanic

    the mekanic Major Mekanical Geek

    Last edited: Apr 7, 2009
  11. Cordialis

    Cordialis MajorGeek

    I don't get it. What's that with your second link (SAS)? Your MBAM link is identical to mine above. I'm not capable of advising about changing BIOS settings in regard to booting. That's why I didn't. I just mentioned it. :major
     
  12. the mekanic

    the mekanic Major Mekanical Geek

    Erring on the side o' caution. I figured whynot cover all bases?
     
  13. alpha202ej

    alpha202ej Private E-2

    Have you tried running combofix yet? When I cannot access explorer to use combofix, I see if I can still bring up task manager. If I can, I burn combofix to a CD and copy it to my hard drive. From there I rename the file to something other than combofix, becuase some malware prevents combofix from running. I like to rename it to cf.exe. If you are able to run it that way you might be able to get some results.
     
  14. the mekanic

    the mekanic Major Mekanical Geek

    Way above...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds