• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5748
  • Last Modified:

Winlogon.exe error then Blue screen shut down when connected to internet

when i start up my laptop i get a winlogon.exe error saying it has encountered a problem and needed to close.
I can only start up my laptop either in safemode or normal mode but with the internet connection off. Once i connect to the internet i get i get a blue screen shut down error saying " STOP: c000021a [fatal system error} The windows logon process system terminated unexectedly with a status of 0xc0000005 (0x00000000 0x0000000)
The system has been shut down.

I've tried running norton 2006 and spy sweeper in safe mode but it i just keep removing the same files that keep reappearing again.

So i can't download anymore antispyware programs since i keep crashing on that blue screen everytime i connect to the internet.

Can some expert please help i dont want to reformat my pc.
0
chanster85
Asked:
chanster85
  • 4
  • 3
1 Solution
 
rpggamergirlCommented:
We could help you better if we could look at your hijackthis log please.

Please download HijackThis 1.99.1
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet,
go here and paste your Hijackthis log --> http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:

Or copy and paste the log at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Post the link to the saved list here.
0
 
chanster85Author Commented:
http://www.rafb.net/paste/results/JS39yh34.html

sorry it took so long... since i cant connect to the net on the lap top , i had to download hijackthis onto this cpu then burn and copy onto the laptop and burn the log file then copy it here... im out of blank cds now..
0
 
rpggamergirlCommented:
Please follow these:

1. Run Hijackthis and put a check next to these entries and click "Fix Checked" button (all browsers closed)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com 
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"  
O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file)  
O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)  
O2 - BHO: (no name) - {00000000-F09C-02B4-6EC2-AD0300000000} - (no file)
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll
O2 - BHO: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - (no file)
O2 - BHO: winapi32.MyBHO - {62E2E094-F989-48C6-B947-6E79DA2294F9} - C:\WINDOWS\system32\winapi32.dll
O2 - BHO: (no name) - {7b55bb05-0b4d-44fd-81a6-b136188f5deb} - (no file)  
O2 - BHO: (no name) - {8333c319-0669-4893-a418-f56d9249fca6} - (no file)  
O2 - BHO: (no name) - {9c691a33-7dda-4c2f-be4c-c176083f35cf} - (no file)
O2 - BHO: (no name) - {e52dedbb-d168-4bdb-b229-c48160800e81} - (no file)  
O2 - BHO: (no name) - {E73B3BFD-BE04-447A-BDCB-B5EF86035139} - C:\Program Files\Windows NT\horedota.dll  
O2 - BHO: (no name) - {ffd2825e-0785-40c5-9a41-518f53a8261f} - (no file)
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard18.exe  
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad18.exe  
O4 - HKLM\..\Run: [0mcamcap] C:\WINDOWS\system32\0mcamcap.exe  
O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe
O4 - HKLM\..\RunServices: [0mcamcap] C:\WINDOWS\system32\0mcamcap.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKCU\..\Run: [0mcamcap] C:\WINDOWS\system32\0mcamcap.exe
O20 - Winlogon Notify: sbtlbr - C:\WINDOWS\SYSTEM32\sbtlbr.dll  
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)


2. Download Killbox:(only a small file)
http://www.atribune.org/downloads/KillBox.exe
*Select the "Delete on Reboot" option.
*Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\system32\0mcamcap.exe
C:\WINDOWS\system32\runsrv32.exe
C:\WINDOWS\system32\susp.exe
C:\WINDOWS\SYSTEM32\sbtlbr.dll  
c:\secure32.html  

*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. If the computer doesn't restart, just restart manually.

3. Please, download Brute Force Uninstaller:
http://www.merijn.org/files/bfu.zip 
and unzip it to it’s own folder folder (c:\BFU)
Run the program and click the Web button located on the top right corner
Copy and Paste the below web address into the address bar of the Download script window:

http://metallica.geekstogo.com/alcanshorty.bfu

Checkmark the following boxes:
*Use settings specified in script for the above option
Execute the script by clicking the Execute button.
Wait for the complete script execution box to pop up and press OK.
Press exit to terminate the BFU program.


After you've done those run SpySweeper again and Norton also, or Download Ewido.
Download and install the free version of Ewido anti-malware.
http://www.ewido.net/en/download/
Update first then scan in safe mode.

Post a new hijackthis log for review.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
chanster85Author Commented:
Thanks rpggamergirl, ive done the hi jacking part but i wont be able to continue because i still cant access the internet on the messed up laptop and im all out of blank cds..... dont have any floppy drive on the laptop either, so i might have to wait till tommorrow until i can get some blank cds. Unless if theres another way to transfer data from one pc to another without the wireless internet.
0
 
rpggamergirlCommented:
No flash drive? or usb stick?
Oh OK, just get more blank CDs then, CDRW would be handy, :)
0
 
chanster85Author Commented:
Ok went to walmart and got some more cds, they didn't sell usb sticks i was looking for them..

heres the log link http://www.rafb.net/paste/results/3FtNTk23.html

Everything seems to be working fine now.
i had to uninstall norton to get the internet back since the virus/spyware jacked it all up
norton sux
but you rock rpggamergirl!
keep up the good work
0
 
rpggamergirlCommented:
Your log is clean!

Thanks for the compliments, very much appreciated, and yeah Norton suck we used to have it till our pc got infected eventhough we were very careful and auto-protect was always on with updated virus definitions.

You did a good job cleaning your pc and without internet connection, :)
Great work!
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now