jvuz Posted June 18, 2013 Share Posted June 18, 2013 Hi,I'm having a problem with some of our pc's. The moment you logon, it immediately logs off. I already checked the registry for the userinit value, I also replaced already the userinit and the explorer.exe but still no avail. Now, when I try to logon into the domain, I get the message that the netlogon service hasn't started. Somebody ahs a clue what I could do next?Jvuz Link to comment Share on other sites More sharing options...
submix8c Posted June 18, 2013 Share Posted June 18, 2013 (edited) More than ONE Computer?The "fix" you describe is confusing.1 - Logon then immediate Logoff2 - You replaced the two EXE files and NOW get "in" (#1 fixed) but NetLogon service not startedIs the above correct? If so, it sounds very much like you got a trojan/virus that SPREAD among several computers across your network. Your WINLOGON.EXE could also be affected as well as many other System files if so.THIS is the "fix" you have done so far?http://en.kioskea.net/forum/affich-22087-xp-auto-log-offI'm also going to ask - can you get into the Security Center and is your "Automatic Updates"/"Windows Firewall" accessible?edit - Do a search on "wsaupdater". had a bad time w/ a friend's PC and had to resort to using a GOOD AntiVirus + Spybot + Malwarebytes to even get it (maybe) "clean". MANY more trojans were found beyond that - not trusting it even so, so I'm reloading it. Repair Installs do NOT get rid of the "random named" bad files. SFC only works in Normal mode, not Safe mode. Edited June 18, 2013 by submix8c Link to comment Share on other sites More sharing options...
jvuz Posted June 20, 2013 Author Share Posted June 20, 2013 No, I don't get in, I tried with several users, but I can't get in.The link you gave i tried already, no avail. Link to comment Share on other sites More sharing options...
submix8c Posted June 20, 2013 Share Posted June 20, 2013 WHAT do you MEAN "can't get in" - you mean you can NOT sign on AT ALL after the "fix"? By what METHOD did you try the "fix"? HOW much did you "fix"?I gave that link as an EXAMPLE! The problems go MUCH deeper than that.You-appear-to-have-a-nasty-TROJAN!I used a LiveXP and a GOOD AntiVirus (installed on MY computer) and used Local Network Share to scan the INFECTED computer. I ALSO (while running the LiveXP) deleted the contents of ALL Temp/Temporary Internet folders. Before that, the Trojan was INFECTING the SpyBot/MBAM. You CAN use a LiveLinux as well.Easier way -Stick that HDD into a GOOD computer (freshly installed on a Primary HDD) as a Secondary with MBAM/SpyBot(v1.6 + the definitions)/AntiVirus (get a trial of Symantec - that's the one that found most of them) installed NOT CONNECTED to the Internet. THEN do a Repair Install. Then PRAY after sticking it BACK into the Original computer and RE-RUNNING! MBAM/Spybot.You'll have to do that with EVERY infected PC. TAKE THEM OFF OF THE NETWORK or risk infecting "everyone" all over again! Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now