winlogon regkey

  • Thread starter Thread starter joe
  • Start date Start date
J

joe

Hello,

Because of a panic action after the latest virus outbreak we deleted by
accident the winlogon regkey that contains a reference to userinit.
The pc still appears on the network with the drives exposed but logon is
immediately followed with logoff. Unfortunately for security reasons the
remote reg service was disabled. Anyone know how we could fix the registry
remotely ? We still have harddisk access :)

Kind regards,
Joe
 
You could load the system hive into regedt32. (assume you have access to the
data on the disk.)
Then edit it and copy it back.
If you cant access the data you could use this drive as a slave disk in
another machine and perform the edit. Then place it back as the master into
the original machine.


The hives can be found in: winnt\ system32\config
 
Back
Top