• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

XP immediately reboots after login

Strikemaster

[H]ard|Gawd
Joined
Mar 29, 2001
Messages
1,264
This is a fun one!

Customer machine was cleaned of spyware and the Sasser virus. During the process (I wasn't here, but I've got the leash on this dog now :( ), the dratted thing will now IMMEDIATELY reboot after passing the login screen, both in Safe Mode and normal. Have tried variations of the Safe mode, such as Safe mode w/ command prompt, but nothing affects it. Something flashes by, doesn't look like a BSOD, then you get the "Saving user settings" message and restart begins.

Programs I assumed were used:

SpyBot 1.3
CWShredder 1.57
AdAware 6.0 build 181 w/ 06.02.04 reflist

Any ideas, 'cause I'm fresh out, and Google has been a waste of time w/ all the Sasser / Blaster hits.
 
does it reboot immediatly or does it say this machine will reboot it x seconds and then reboot?

if you have a few secs you can go do a start>> run>> shutdown /a

which will stop the shutdown
 
Immediate and unconditional. :eek:

No "NT Authority" countdown; click on the name, give it a password if needed, then watch as it states "Logging in..." then "Saving User Settings..." and reboot occurs. At least with the Safe Mode Command Prompt version, I can see the command window open for a split second before the shutdown sequence occurs.
 
Don't know why people refuse to check this, but if you can boot in Safe Mode, go right to the Event Viewer and see what's in there. More often than not, it will tell you exactly what crapped out.
 
I had something similar to this happen after cleaning a machine with the same version and def files of adaware. it said it had to clean something on reboot, then when it rebooted, and I tried to login, it would just log right back out. This one didn't restart, though. I ended up just putting the harddrive in another machine to backup files, and then rebuilt it. It needed it anyway. Maybe you could just try a repair install?
 
djnes said:
Don't know why people refuse to check this, but if you can boot in Safe Mode, go right to the Event Viewer and see what's in there. More often than not, it will tell you exactly what crapped out.
Check the first post. The machine does this in ANY mode, be it normal, safe, safe w/ command prompt, etc ad nauseum. It will not boot into anything useable; the instant it displays the desktop background in Normal mode, it logs the user off. In Safe modes, it jumps straight to logging off the user (Administrator account included).

Sorry if I'm coming off snappish, this sucker is really torquing me off. An XP P.O.S. is proving my tech-fu to be deficient. It's like a ninja finding out he just got handed a rubber katana... :rolleyes:
 
I misread it to mean you could get in to Safe Mode. If your spending this much time on it, then why not backup the data and rebuild?

If everyone who worked on computers would get a copy of Norton Ghost Corporate, you could backup data and have a fresh image installed in less than 10 minutes. I'd suggest everyone run off to a computer show and get a copy.
 
So since I assume a kernel debugger is right out, (Unless your kung fu includes kernel debugging) What happens if you use last known good from the F8 menu?
 
Yes F8 at beginning of boot and Last Known Good is a start (if you haven't tried that already). How about this. Since it is something starting up after login, it is NOT a service. Have you tried holding down shift at logon? Shift stops autorun but it also stops (sometimes) startup items that maybe giving you grief. Have you tried logging on under a different username (if any are available)? Maybe it's something specific to that profile.

XP Repair maybe needed. If you know the file that is starting you can boot with an NTFS Dos disk or put the drive in another computer and remove the offending file. This is assuming you're running NTFS. If fat, then boot off a 98 disk and delete it.

Good luck.
 
Also if you have a network and you have NOT disabled remote registry and have remote administration enabled, you might be able to load the registry on another computer on your network and remove the offending startup items.
 
I got a good possibility on this one.

Check under
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] and similar areas of the registry for a value like (it's been a while, so I might only be somewhat close)

rundll win32.dll exitwindows ...

For a gag, I once stuck something like that under "runonce" (so it wouldn't repeat every time) on a coworker's machine and when I wandered in later that morning, it was all I could do to keep a straight face as he told me how his computer had shut down upon logging in.
 
Also the log on log off problem can result from XP Activation problems. Check into making sure they have a legit copy of XP.
 
It sound like you need to run a repair or access the repair console from the CD setup.

Cheers,
 
Hmm, an excellent list to try on the beast when I get in the office Monday.

The machine is a customer's home computer, brought in for virus removal and spyware eradication. The thing is a vomit-filled Petri dish of Netsky, Sasser, CoolWebSearch variants galore, pr0n dialers and online casino worms. Believe me, I'd love to push the thing right back on the customer with a full-case condom over it, instructions for repair beginning with "FORMAT C: /U", and the modem / ethernet ports filled with J-B Weld to prevent reinfection. :D

The boss, however, does not agree with my assessment... :rolleyes:

Recap: XP home machine immediately logs off the user after login, irrespective of user or OS mode of operation. Administrator in Safe Mode - Command Prompt, or user in Normal after entering the password, the result is the same: you're staring at the Welcome / Login page again.
 
boot off the xp cd and select repair console. rebuild the boot partition and that should allow boot to safe mode and then begin clean up


Another suggestion would be that you could boot off of a Knooppix Linux cd and access your data files as well as burn them to a disc.Then you could reformat.

http://www.knoppix.org/
 
I had a similar situation happen to a laptop after i removed some nasties from it.. It would boot up fine, and when i logged on, it would immediatley log off. After trying many things, i booted the xp cd, and repaired the installation of xp, and then it booted up fine and the system was exactly as it was before it broke.
 
Ive seen this happen quite a bit lately. This only happens after login.

The fix is to remotely edit the registry from another workstation.

Go to hklm\software\microsoft\windowsnt\current version\winlogon\notify\ remove any key with guardianxxx and then reboot the computer.

This has resolved this issue on every workstation that I have worked on with this issue.
 
OK, bump to the first page.

The original machine was removed by the owner before we finished trying to recover it, but another one has been brought in with the same issues. Again, with ALL user logins, you click on the name, the screen changes to the Login animation, you get a glimpse of the bare desktop, and immediately the screen changes to Logging Off / Saving Settings. You are then presented with the screen of available user logins.

Have tried the options listed, using a ERD disk we had for WinXP Pro.

Nothing out of the ordinary found in HKLM/Software/Microsoft/Windows/CurrentVersion/Run or HKLM/Software/Microsoft/Windows NT/Winlogon. No "Guardian" entries noted.

Answer Found! :D

From this link: Open Tech Support

Posted by: rib0n

HERE IS THE FIX

1. Navigate to
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"

2. If there is a key named "OldUserinit", delete the "Userinit" key and rename the "OldUserinit" key to "Userinit".

3. The "Userinit" key should now say
"WINDOWS_PATH\system32\userinit.exe,"

"WINDOWS_PATH" is relative to where you have your windows installed.
Mine would be "C:\WINDOWS\system32\userinit.exe,"

Now you can log in again

Who changed my Userinit key?

Spyware. The program is called "Search Assistant" and is located at "\Program Files\WindowsSA". It also has some "omni*.*" files in "\WINDOWS\system32\" dir that are linked to "Userinit" key. If you remove this spyware (using Ad-aware, etc.) the "omni*.*" files are deleted and you can't log in.

An alternate method is to access the disk, copy userinit.exe to wsauserinit.exe (the spyware file in %windowsroot%\System32) and reboot.
 
Back
Top