PDA

View Full Version : User Accounts does not open - am I being hacked ?


Jason
December 14th 03, 11:21 AM
Problem may be virus or hacker related. User Accounts
just does not open.

In early June I had W32.KLEZ.H infecting my WinXP SYSTEM
RESTORE and NAV 2003 kept cleaning W32.VALLA.2048 from
about 100 WIN\SYSTEM32 exefiles at each reboot. Finally
used SYSTEM RESTORE to revert back to before the
infection, but several SYSTEM32 files remain dated June 6.

Current problem is as follows : A few WinXP accessories
just plain do not open when double clicked, REGEDIT.EXE,
CALC.EXE come to mind, but the worst is User Accounts in
Control Panel. I execute and it hour-glasses for 0.5 sec
and then nothing opens. I have read a few posts and also
tried the MyComputer left click MAANAGE suggestion, but
LOCAL USERS AND GROUPS is not a selection option. Also
exists in safe mode.

Also using TWEAKUI, I find a user ASPNET that does not
appear at login.

I suspect that I have been hacked (maybe some base dll
blocking my out) and want to try to get back into User
Accounts. Any tests I can do or advice ?

Miha Pihler
December 14th 03, 11:21 AM
Hi Jason,

Make sure you are not infected any more. Files in system restore can also be
infected and restoring from them doesn't make your files clean. So run again
antivirus tests...

ASPNET is built-in user account used for running ASP.NET and does not show
up on Welcome Screen.

--
Mike
MCSA 2K, MCSE 2K, MCT, ...

"Jason" > wrote in message
...
> Problem may be virus or hacker related. User Accounts
> just does not open.
>
> In early June I had W32.KLEZ.H infecting my WinXP SYSTEM
> RESTORE and NAV 2003 kept cleaning W32.VALLA.2048 from
> about 100 WIN\SYSTEM32 exefiles at each reboot. Finally
> used SYSTEM RESTORE to revert back to before the
> infection, but several SYSTEM32 files remain dated June 6.
>
> Current problem is as follows : A few WinXP accessories
> just plain do not open when double clicked, REGEDIT.EXE,
> CALC.EXE come to mind, but the worst is User Accounts in
> Control Panel. I execute and it hour-glasses for 0.5 sec
> and then nothing opens. I have read a few posts and also
> tried the MyComputer left click MAANAGE suggestion, but
> LOCAL USERS AND GROUPS is not a selection option. Also
> exists in safe mode.
>
> Also using TWEAKUI, I find a user ASPNET that does not
> appear at login.
>
> I suspect that I have been hacked (maybe some base dll
> blocking my out) and want to try to get back into User
> Accounts. Any tests I can do or advice ?

Google