troubleshooting Question

XP Pro logon disabled (by trojan horse?) - Logon - Logoff loop

Avatar of Vamp9190
Vamp9190 asked on
Windows XP
29 Comments1 Solution7202 ViewsLast Modified:
I CANNOT logon Windows XP Pro - I have a very good idea of the problem - Ad Aware SE (not version 6) tried to remove a trojan horse - I'm not positive
it was Blazefind -- (the Troj is still on my sys) and now my registry points to a file that is not there -- bottom line is that winlogon.exe is compromised
and everytime I try to logon, it tries to 'load personal settings' and then the PC clicks off / reboots - I have already tried the XP Recovery console FIX
described below.

please HELP

the below solution is from this site link:
http://www.winxptutor.com/wsaremove.htm

[Unable to logon to Windows after removing BlazeFind using a spyware removal utility?
Logon - Logoff loop, also caused by BlazeFind
Another critical symptom caused by this malware: This malware modifies the Userinit area in the registry (replacing the userinit.exe with wsaupdater.exe) and Ad-Aware (with a particular definition update) removes the wsaupdater.exe file from the system, thus causing the Logon - Logoff loop. That is, when you login to Windows, the 'loading personal settings" verbose will appear, but suddenly it will logoff. This issue was documented clearly by Lavasoftusa in it's Lavahelp Knowledgebase.
Here is the solution to the logon - logoff issue in Windows XP.
Enter the Recovery Console
Boot the system using the Windows XP CD-ROM. In the first screen when the Setup begins, read the instructions press "R" (in the first screen) enter the Recovery Console. Type-in the built-in Administrator password to enter the Console. You'll see the prompt reading C:\Windows (Or any other drive-letter where you've installed XP)
Type the following command and press Enter.
CD SYSTEM32
(If that does not work, try CHDIR SYSTEM32)
COPY USERINIT.EXE WSAUPDATER.EXE
Quit Recovery Console by typing EXIT and restart Windows.
You'll be able to login successfully as you've created the wsaupdater.exe file (now, a copy of userinit.exe)
Now, change the USERINIT value in the registry (see Phase II in this page) and change it accordingly.]


I tried this fix -- IT DID NOT WORK -- I still get the LOGON / LOGOFF loop when XP is 'loading personal settings' forn the logon screen
I need to get back into Windows - and if I do - whats the best program that will remove this trojan horse - the program AVS found it,
(I have been able to get back in windows once and ran the virus scan - but then PC rebooted and same problem) but said 'not removable.'

Thanks
ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 1 Answer and 29 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 29 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros