This is a read-only archive. No new posts or registrations. Privacy Page
Software

Can't Get Past Login Screen

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I've XP Pro and have had no problems, up until when I ran Registry Mechanic and it repaired this (copy of scan log): Registry Mechanic 4.0.0.100 —————————————————————————————————- Start of Scan 7/04/2007 16:52:34 Your System Information : CPU: Intel Pentium IE: Internet Explorer 6.0.2900 MEMORY FREE: 351888 MEMORY TOTAL: 654832 VIRTUAL FREE: 2032900 VIRTUAL TOTAL: 2097024 WINDOWS VER: Windows XP 5.1 (Build 2600) —————————————————————————————————- Running processes: Process ID —————————————————————————————————- [System Process] 0 System 4 smss.exe 820 csrss.exe 884 winlogon.exe 908 services.exe 952 lsass.exe 964 svchost.exe 1140 svchost.exe 1212 svchost.exe 1328 InCDsrv.exe 1356 svchost.exe 1588 svchost.exe 1672 explorer.exe 1844 spoolsv.exe 1940 nod32kui.exe 400 ipoint.exe 416 InCD.exe 396 BLuPro.exe 452 rundll32.exe 464 Bkav2006.exe 480 schedul2.exe 1968 DkService.exe 2032 nod32krn.exe 628 nvsvc32.exe 644 scsiaccess.exe 664 sdhelp.exe 732 svchost.exe 708 WRSSSDK.exe 1440 alg.exe 2640 RegMech.exe 3100 —————————————————————————————————- Sections Scanned: —————————————————————————————————- CC - 1 Location: HKEY_CLASSES_ROOT\TypeLib\{0DC15147-48EB-4E93-8628-E89A27971444}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 2 Location: HKEY_CLASSES_ROOT\TypeLib\{1459DC40-3D8F-4890-BAA8-E7EFC2FC3528}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 3 Location: HKEY_CLASSES_ROOT\TypeLib\{163D3064-A55E-4BCE-A265-FD2888110DDB}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 4 Location: HKEY_CLASSES_ROOT\TypeLib\{953914FF-7BEB-4293-82A7-A5CCFCA12FCB}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 5 Location: HKEY_CLASSES_ROOT\TypeLib\{A267CDB5-B892-4F2F-B1C8-21AB9AAF4C01}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 6 Location: HKEY_CLASSES_ROOT\TypeLib\{EF1C62E7-31F3-44C7-ACED-7F5ABEDB3347}\2.0\HELPDIR Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0 CC - 7 Location: HKEY_CLASSES_ROOT\TypeLib\{0DC15147-48EB-4E93-8628-E89A27971444}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd CC - 8 Location: HKEY_CLASSES_ROOT\TypeLib\{1459DC40-3D8F-4890-BAA8-E7EFC2FC3528}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd CC - 9 Location: HKEY_CLASSES_ROOT\TypeLib\{163D3064-A55E-4BCE-A265-FD2888110DDB}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd CC - 10 Location: HKEY_CLASSES_ROOT\TypeLib\{953914FF-7BEB-4293-82A7-A5CCFCA12FCB}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd CC - 11 Location: HKEY_CLASSES_ROOT\TypeLib\{A267CDB5-B892-4F2F-B1C8-21AB9AAF4C01}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd CC - 12 Location: HKEY_CLASSES_ROOT\TypeLib\{EF1C62E7-31F3-44C7-ACED-7F5ABEDB3347}\2.0\0\win32 Value : default = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\Word8.0\MSForms.exd SL - 13 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache Value : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_0\AUTOPLAY\DOCS\vlc.exe = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_0\AUTOPLAY\DOCS\vlc.exe Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_0\AUTOPLAY\DOCS\vlc.exe SL - 14 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache Value : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_1\AUTOPLAY\DOCS\vlc.exe = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_1\AUTOPLAY\DOCS\vlc.exe Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\ir_ext_temp_1\AUTOPLAY\DOCS\vlc.exe SC - 15 Location: C:\Documents and Settings\WIN06V2\Application Data\Microsoft\Office\Recent\2X3QEB4I.LNK\ Value : Shortcut = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\2X3QEB4I Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\2X3QEB4I SC - 16 Location: C:\Documents and Settings\WIN06V2\Application Data\Microsoft\Office\Recent\EWLNF512.LNK\ Value : Shortcut = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\EWLNF512 Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\EWLNF512 SC - 17 Location: C:\Documents and Settings\WIN06V2\Application Data\Microsoft\Office\Recent\Hartman[1].ppt.LNK\ Value : Shortcut = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\NLMOB4S2\Hartman[1].ppt Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\NLMOB4S2\Hartman[1].ppt SC - 18 Location: C:\Documents and Settings\WIN06V2\Application Data\Microsoft\Office\Recent\NLMOB4S2.LNK\ Value : Shortcut = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\NLMOB4S2 Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\NLMOB4S2 SC - 19 Location: C:\Documents and Settings\WIN06V2\Application Data\Microsoft\Office\Recent\Q4JMI588.LNK\ Value : Shortcut = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\Q4JMI588 Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\Q4JMI588 FX - 20 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.met\OpenWithList Value : default = blank Parsed : DEEP - 21 Location: HKEY_CURRENT_USER\Software\Microsoft\FrontPage Value : WecErrorLog = C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\wecerr.txt Parsed : C:\DOCUME~1\WIN06V2\LOCALS~1\Temp\wecerr.txt DEEP - 22 Location: HKEY_CURRENT_USER\Software\Ahead\Nero - Burning Rom\Settings Value : DefaultImagePath = C:\Documents and Settings\WIN06V2\My Documents\TempImage.nrg Parsed : C:\Documents and Settings\WIN06V2\My Documents\TempImage.nrg DEEP - 23 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\MediaGuide Value : CachedIconPath = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\H9WTWOOP\wm_com_v_rgb_15x15[1].png Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\H9WTWOOP\wm_com_v_rgb_15x15[1].png DEEP - 24 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\MediaGuide Value : CachedLargeLogoPath = C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\87BLV373\WindowsMediaPlayer11_30x30[1].png Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Temporary Internet Files\Content.IE5\87BLV373\WindowsMediaPlayer11_30x30[1].png DEEP - 25 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace Value : LocalDelta = C:\Documents and Settings\WIN06V2\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSD.XML Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSD.XML DEEP - 26 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace Value : RemoteDelta = C:\Documents and Settings\WIN06V2\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSR.XML Parsed : C:\Documents and Settings\WIN06V2\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSR.XML DEEP - 27 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Value : Userinit = C:\WINDOWS\system32\userinic.exe,userinit.exe Parsed : C:\WINDOWS\system32\userinic.exe —————————————————————————————————- Registry Mechanic 4.0.0.100 —————————————————————————————————- End of Scan 7/04/2007 16:59:23 Your System Information : CPU: Intel Pentium IE: Internet Explorer 6.0.2900 MEMORY FREE: 351888 MEMORY TOTAL: 654832 VIRTUAL FREE: 2032900 VIRTUAL TOTAL: 2097024 WINDOWS VER: Windows XP 5.1 (Build 2600) When I now start up windows, it boots momentarily into the desktop and then back to a login screen, I press the administrator icon, but it logs on, then off again, this happens repeatedly. I've never set this OS to go into a login screen-just straight into the desktop. I also have tried booting into safe mode, but the same thing happens. I can't get into my OS now. Please I need a fix to repair and reverse whatever RM did, could it have something to do with the last scan entry, #27?
Hi,
Sorry to hear of the problems with your machine,

I am not too happy with the presence of userinic.exe in your system root (Deep 27) as this has often been associated with malicious elements of a Trojan Horse type nature.

I think you need the advice of a trained and experienced malware removal expert to check this out for you and either put your mind at rest on this point or provide specific guidance on how to proceed.

I suggest you go here to our Malware Removal forum:
http://forums.tomcoyote.org/HijackThis_Log…emoval_f27.html

Once your machine has been declared clean then please feel free to post back here if you have any non malware related issues and we will do out utmost to asssist.

The experts on the malware forum often get snowed under as there are often more folks requesting assistance than trained and experienced volunteers available, so if you can, please try and be patient, as they will get round to your post as soon as they possibly can.
Regards
paws
That's the problem Chief, I can't get into the OS, so how can I post a Hijack This log? I could get into my OS, up until I ran that Registry Mechanic scan.
Hi, That's understood, at this stage just post your message and say you can't boot into Windows and the malware expert will take it from there. There are some suggestions we could make here, but I think its best to let the malware expert have a look at your post without us here making any suggestions that could possibly conflict. If the malware expert recommends you come back here we will be very happy to assist. Regards paws

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI