ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
wa8okr


Joined: 25 Nov 2007
Posts: 0
Location: Stow, Ohio
Reply with quote
keitho64 thanks I would like to look at the information when you can get to it. I am desperate now the XP machine is my main computer and I would like to keep from reformatting if possible.

GuitarBob I can not boot from anything even Admin I may have lost winlogin and do not know it. I would like to know more about your 3rd party snapshot.

Woukd it help me if I were to borrow a straight xp sp2 disk from somebody and tried a repair?

Bill Question
View user's profileSend private message
Gdub


Joined: 09 Jun 2006
Posts: 0
Location: Melbourne Australia
Reply with quote
keitho64 wrote:
I had the same problem this weekend. I have clam configured to move infected files and I have my machine configured to shut down nightly. Without userinit.exe the machine would not boot, it was in a loop for loading the profile and would not come up in safe mode as Admin either. I will also add that I have my clam configured to email me anytime it finds a virus so I knew what to look for.

In order to reload userinit I did the following

I booted the XP CD
Select R for recovery mode
at the prompt select the windows instance to login to, I only have 1
You must have the administrator password, type it in
at the prompt cd to windows\system32
at the C:\Windows\Sysyte32 prompt enter "expand x:\I386\userinit.ex_" substitute X with the drive of the CD
this will uncompress the original source file into the windows\system32 directory.

You can use this procedure for any other source file that was deleted but make sure you execute the command from the destination directory or add the destination directory to the command line.

Once I did this I was able to reboot and the machine has been fine since. I am still getting the false positive on USERINIT and CD32 but I modified Clam to just warn me of the virus for now. Once a new data file comes out I can change it back.

Keith


This is EXACTLY the issue i am having so i have tried to follow the steps as detailed in the post i have quoted.

One problem though, my DOS language skills are shissenhaussen to say the least and the commands listed here are either incomplete or have typo's so i cant get them to work.

Can anyone help me by replying with exactly what i need to type in on each step within the recovery console?

I have 4 pc's effected by this problem and need to get cracking on repairing them.

All help is greatly appreciated!

Gareth
View user's profileSend private message
Gdub


Joined: 09 Jun 2006
Posts: 0
Location: Melbourne Australia
Reply with quote
Ok, i managed to fluff my way through the dos stuff ...

C:\Windows\Sysyte32 prompt enter "expand x:\I386\userinit.ex_" substitute X with the drive of the CD
this will uncompress the original source file into the windows\system32 directory.


When i type in the expand command i get a response of "There is no floppy disk or CD in the drive"

My cd/dvd drive is E:\ on this pc which is what i typed into the command. The XP CD is in the drive so i dont understand why it would return this message.

Starting to get a little confused and frustrated!

Can anyone set me straight?

G
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Wa80kr, a snapshot will not help unless it is installed at the time a problem occurs. There may be some free ones, but all I've seen that are any good are commercial.

You might see if you could get one of those Linux boot disks. Each of the major AVs has one. They are used when a virus has destroyed a machine to find/kill it from the Linux OS. They may have some capabilty to look at your system, and if you know where the lost file is (ClamWin quarantine), you might be able to copy/move it to its original directory. That might be asking quite a bit of it, however, since the are mainly for virus eradication. I've used Dr. Web's to find viruses.

Regards,
View user's profileSend private message
Logoff loop solved
dwwolfe


Joined: 21 Jul 2009
Posts: 0
Location: Chapel Hill, NC
Reply with quote
I had the same problem yesterday morning when I restarted my computer to boot into linux. When I tried to log back into Windows XP it was immediately logging off

From reading online, I suspected the problem was something to do with userinit.exe. I checked the registry by booting up under linux (use knoppix unless you have a dual boot) and copying the registry files to a network drive (located in C:\Windows\System32\config). Using a working version of windows registry editor I loaded the Software hive from the broken computer and found the logon registry key (HKEY_LOCAL_MACHINE >> SOFTWARE >> Microsoft >> Windows NT >> CurrentVersion >> Winlogon). However, this appeared fine and was still pointing at C:\Windows\System32\userinit.exe

I searched the windows drive under linux for userinit.exe and only found it in the clamwin quarantine. At this point it was obvious what happened. A simple cp command copied the file from the quarantine back to C:\Windows\System32\userinit.exe and Windows has worked fine ever since

After wasting 2 hours of my morning fixing my computer I decided to switch antivirus solutions. In my opinion, an antivirus program should AVOID situations where your computer is brain dead, not create them. If someone didn't find out the real cause of this problem they would have no option other than to try a windows recover (good luck) or do a complete reinstall. The average user is not likely to solve this problem on their own

By the way, make sure that you can open Notepad (Start -> Programs -> Accessories -> Notepad). If not, check the quarantine folder
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
DW said:

[In my opinion, an antivirus program should AVOID situations where your computer is brain dead, not create them. If someone didn't find out the real cause of this problem they would have no option other than to try a windows recover (good luck) or do a complete reinstall. The average user is not likely to solve this problem on their own]

Well said, DW! Your explanation of what you did in Linux may help someone. I had to do a reinstall a couple of years ago.

Regards,
View user's profileSend private message
wa8okr


Joined: 25 Nov 2007
Posts: 0
Location: Stow, Ohio
Reply with quote
keitho64: Can you or anyone else supply me with the method to download ?? to create an XP bootdisk?

Thanks

Bill
View user's profileSend private message
wa8okr


Joined: 25 Nov 2007
Posts: 0
Location: Stow, Ohio
Reply with quote
Hi All: I have found that if I were to download a boot disk for sp2 it would do the same thing as the recovery disk as an original XP instalation. The hard drive would be formatted and I would lose all my data and software. This would mean a complete rebuild and maybe even purchase of some software re-purchase.

I have a pc guy who says he can take my HD and connect it to his operating pc and work on the HD to get the files working again? We will see!

Is there any need to be concerned about the CB32.exe file if Nobody uses Netmeeting?

Bill
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
I don't think you need to be concerned about that file if no one uses the application. You can always reinstall the application after you get the system up and running. I suppose you have considered trying the Linux boot disk route to see if you could access your file structure and do something from it.

Regards,
View user's profileSend private message
Another False Positive?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 2 of 2  

  
  
 Reply to topic