Cannot login - it logs me out immediately

G

Guest

I have an oem version of Windows XP Home that has been upgraded to SP2.
Something happend and now I cannot login to any accounts since it just logs
me out again. I have tried copying the file in system32\userinit.exe to
wsaupdater.exe and then logging in Safe mode however this did not solve the
problem. Anyone know what my options may be?
 
S

Sharon F

I have an oem version of Windows XP Home that has been upgraded to SP2.
Something happend and now I cannot login to any accounts since it just logs
me out again. I have tried copying the file in system32\userinit.exe to
wsaupdater.exe and then logging in Safe mode however this did not solve the
problem. Anyone know what my options may be?

You don't want the wsaupdater.exe file. You want it gone. It is a part of
the "blazefind" malware. Delete it. This file doesn't replace userinit.exe.
That is a protected system file and unless this malware has become more
sophisticated (always possible), it leaves it alone.

What wsaupdater does, is it adds itself to a registry key involved with the
logon process and that should contain a reference to userinit.exe only.

Below is a link to a page by MVP Rick Rogers that explains how to fix this
problem. It's a bit of tricky fix if not too computer savvy. If that's the
case, may need someone locally to help with all of the steps.

http://rickrogers.org/fixes.htm#Blazefind
 
G

Guest

Thanks Sharon. Basically that is what I had done. I followed Rick's
site: used my Windows SP PRO cd and entered into recovery mode; then C:\copy
system32\userinit.exe system32\wsaupdater.exe as that site suggests; then
exited into SAFE mode and still had the same problem. Would using the PRO
cd be causing an issue? I also tried the 6 cd recovery process but ran into
the problem with the install on disk 3. Any other suggestions?
 
S

Sharon F

Thanks Sharon. Basically that is what I had done. I followed Rick's
site: used my Windows SP PRO cd and entered into recovery mode; then C:\copy
system32\userinit.exe system32\wsaupdater.exe as that site suggests; then
exited into SAFE mode and still had the same problem. Would using the PRO
cd be causing an issue? I also tried the 6 cd recovery process but ran into
the problem with the install on disk 3. Any other suggestions?

Using the Pro CD should not be a problem. Does the copy finish or is there
an error message? The command basically leaves the wsaupdater.exe in place
but changes it contents to match that of userinit.exe. That should lead to
a successful logon since the malware file (its contents anyhow) are gone.

What may be happening is that you've hit on some new malware (a new variant
of this) that can no longer be repaired in the usualy manner. Or there may
be multiple infestations - in other words, wsaupdater may not be the only
problem so even after following the directions you're still stuck.

Sorry, no other ideas other than heading of to one of the spyware forums
and let them have a go at it.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top