<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Found a Fix &#187; Malware</title>
	<atom:link href="http://www.ifoundafix.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ifoundafix.com</link>
	<description>Where Answers are Found!</description>
	<lastBuildDate>Fri, 03 Feb 2012 10:27:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Windows logs off immediately after logging in</title>
		<link>http://www.ifoundafix.com/2010/01/27/windows-logs-off-immediately-after-logging-in/</link>
		<comments>http://www.ifoundafix.com/2010/01/27/windows-logs-off-immediately-after-logging-in/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 14:22:00 +0000</pubDate>
		<dc:creator>ifoundafix</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Desktops]]></category>
		<category><![CDATA[Laptops]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.ifoundafix.com/?p=484</guid>
		<description><![CDATA[When logging into windows, it immediately logged off automatically. It was not possible to access windows, even in Safe Mode. This was caused by a virus, which had hijacked the log on process.]]></description>
			<content:encoded><![CDATA[<p>The other day while browsing the Internet I Found A Fix for a recent problem I was having. The issue is described as follows:</p>
<p>The problem was when logging into windows, it immediately logged off automatically. This was the same for each user account and even attempting to log in using Safe Mode.</p>
<p>This turned out to be due to userinit.exe not running correctly. A virus had hijacked the log in process, running its own executable instead of userinit.exe. A registry key referencing userinit.exe had been altered.</p>
<p>The solution is as follows:</p>
<p><span id="more-484"></span></p>
<p>The obvious difficulty is that I could not log on to the PC to access and edit the registry. To get around this a bootable CD such as Hiren Boot CD or BartPE is required.</p>
<p>To edit the registry of the PC  Boot int Windows PE or Minid XP on the device.<br />
Once in Windows go to the command prompt and  type regedit.<br />
Select HKEY_LOCAL_MACHINE.<br />
On the File menu, choose Load Hive.</p>
<p>A series of message boxes might appear that stating that the folder cannot be found and that the location is unavailable. Ignore any such messages and click OK when they appear.</p>
<p>The Load Hive dialog box will appear.<br />
In the Files of type box, select All Files.<br />
Navigate to the registry location on the local PC. Typically this is C:\WINDOWS\system32\config.</p>
<p>In this config folder, select the hive SOFTWARE and then click OK.<br />
Back in the Load Hive dialog box type a Key Name, e.g., TEST_ITEM.</p>
<p>Choose HKEY_LOCAL_MACHINE, and then choose the new reg key .</p>
<p>Browse to:<br />
&#8220;HKEY_LOCAL_MACHINE\TEST_ITEM\Microsoft\Windows NT\CurrentVersion\Winlogon&#8221;</p>
<p>Look for a a key named &#8220;OldUserinit&#8221;, delete the &#8220;Userinit&#8221; key and rename the &#8220;OldUserinit&#8221; key to &#8220;Userinit&#8221;.</p>
<p>The &#8220;Userinit&#8221; key should be &#8220;C:\WINDOWS\system32\userinit.exe&#8221;.</p>
<p>Usually the problem is that this key is referencing an alternative exe which is causing this automatic log off.</p>
<p>Now clicke HKEY_LOCAL_MACHINE, go to the File menu, and then choose Unload Hive.</p>
<p>Reboot the PC. The log on process should work correctly. However a virus scan needs be run immediately. This is because the problem may reoccur at the next logon (This happened to me)</p>
<p><!--more-->A scanner such as Combofix, Smitfruadfix and/or Malwarebytes should be used. Each of these can be found from a Google search.</p>
<p>After rebooting it is recommended to run an additional scan, perhaps with the installed Anti-Virus program.</p>
<p>I hope you too have Found a Fix!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ifoundafix.com/2010/01/27/windows-logs-off-immediately-after-logging-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Tips for Successful Virus Removal</title>
		<link>http://www.ifoundafix.com/2009/11/24/top-10-tips-for-successful-virus-removal/</link>
		<comments>http://www.ifoundafix.com/2009/11/24/top-10-tips-for-successful-virus-removal/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 11:26:37 +0000</pubDate>
		<dc:creator>ifoundafix</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Desktops]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Laptops]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.ifoundafix.com/?p=363</guid>
		<description><![CDATA[There’s no one way to remove viruses, spyware and general pc problems. Your best bet is to throw as much as possible at these threats. Try the following;  Try Combofix. Disable whatever anti-virus you are currently running first and download here. Visit http://safety.live.com and click on “Full Service Scan”. Follow the steps for a complete [...]]]></description>
			<content:encoded><![CDATA[<p>There’s no one way to remove viruses, spyware and general pc problems. Your best bet is to throw as much as possible at these threats. Try the following; </p>
<ol>
<li>Try Combofix. Disable whatever anti-virus you are currently running first and <a href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe">download here.</a></li>
<li>Visit <a href="http://onecare.live.com/site/en-ie/default.htm">http://safety.live.com</a> and click on “Full Service Scan”. Follow the steps for a complete scan.</li>
<li>After this has completed, go to <a href="http://housecall.trendmicro.com/">http://housecall.trendmicro.com/</a> and Click on “Scan Now. It’s Free”. Again, follow the steps for complete scan and removal of threats.</li>
<li>From the control panel, Go to Add/Remove programs and remove any unnecessary programs. Look out for browser add-ins, search programs, free or demo software, shopping , advertising, toolbar extra’s, and so on. At the very least, this is good pc maintenance. If you have more than 1 ant-virus software, then remove at least one of them.</li>
<li>Download and run <a href="http://www.softpedia.com/get/Antivirus/RogueRemover.shtml">RogueRemover</a>.</li>
<li>Download and Run <a href="http://siri.geekstogo.com/SmitfraudFix.php">SmitfraudFix</a></li>
<li>Download, Install and run <a href="http://www.ccleaner.com/">CCleaner</a> – This is a free tool for removing temporary files, cookies, history, and cleaning up registry problems. Run the Cleaner and then the registry fix.</li>
<li>Download, install and run <a href="http://www.spybot.info/en/download/index.html">Spybot – Search &amp; Destroy</a> &#8211;  Homepage is <a href="http://www.spybot.info/">http://www.spybot.info</a></li>
<li>To analyse and remove items from your startup list,  download <a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis">HijackThis</a> to a temporary directory. This tool is a great way to see what programs are starting up when you pc logs in to windows. My advice here is to remove obvious entries but consult <a href="http://www.google.com/">Google</a> for a second opinion. Be careful with this tool as you can adversely affect genuine programs such as your ant-virus software. Alternatively, you can use the startup manager in CCleaner to simply disable the startup items.</li>
<li>If you do not have any anti-virus software, download <a href="http://free.grisoft.com/">AVG Free</a> .</li>
</ol>
<p>I hope you have Found A Fix!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ifoundafix.com/2009/11/24/top-10-tips-for-successful-virus-removal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

