winlogon regkey

  • Thread starter Thread starter joe
  • Start date Start date
J

joe

Hello,

Because of a panic action after the latest virus outbreak we deleted by
accident the winlogon regkey that contains a reference to userinit.
The pc still appears on the network with the drives exposed but logon is
immediately followed with logoff. Unfortunately for security reasons the
remote reg service was disabled. Anyone know how we could fix the registry
remotely ? We still have harddisk access :)

Kind regards,
Joe
 
You could load the system hive into regedt32. (assume you have access to the
data on the disk.)
Then edit it and copy it back.
If you cant access the data you could use this drive as a slave disk in
another machine and perform the edit. Then place it back as the master into
the original machine.


The hives can be found in: winnt\ system32\config
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top