First kbox induced virus (almost)
Kbox hosed my pc for awhile this morning, but it's at least somewhat fixed now. Here's the skinny:
Yesterday, I backrevved to the last 5.1 agent to fix some MI problems I had with 5.3. No problem installing the 5.1 agent, but I didn't remove the 5.3 agent first because I wanted to see if that would happen automatically. It didn't, so I uninstalled using the msiexec uninstall string. No reboot required and kbox seemed to be working.
This morning, when I logged in as either myself or local admin, it would almost load the desktop, but then log out. Long story short, after 3 hours of troubleshooting with my hard drive slaved to another pc, I discovered that kbox had changed the userinit.exe under winlogon in the registry to kuserinit.exe. I was able to change it back, so now I'm rolling again.
However, I need to backrev our other PCs until we get a working 5.3 agent. Any tips on how to handle for other PCs? Did it happen because I installed the older agent before I removed the newer one? Also, what is kuserinit supposed to do? That seems like a pretty egregious reg change.
Edit: Oh, and meant to point out that a search of kuserinit on the message board brought up 2 old posts, but not a lot of info on kuserinit.
so that the conversation will remain readable.