Total Tayangan Halaman

Rabu, 09 Februari 2011

Verifying and fixing the Userinit value in the registry

In this example, a basic BartPE CD without any Plugins, has been used for illustration purposes. You may add as many Plugins as you want, depending upon your needs.

Verifying and fixing the Userinit value in the registry

If your PC is a victim of the Malware discussed in this article, and unable to login to your profile, then you'll need to fix the registry as discussed there. As you're unable to login, registry modification can only be done from a remote system, or via offline registry editing. This article discusses about offline registry editing.

BartPE screen


Registry Editor


Load Hive option


Select the Hive


Name the Hive


Fixing a key


Unload the hive
  1. Insert the BartPE CD into the drive, and boot the system from the CD. Once the file loading phase is over, the Bart PE desktop will be visible, as shown in Figure 1.
  2. Type Regedit.exe in the prompt, and press Enter. Select the HKEY_USERS hive
  3. From the File menu, choose the Load Hive option. Browse to your Windows installation drive, for example the following location:
C:\Windows\System32\Config\
  1. Select the file named SOFTWARE (the file without any extensions), and click Open
  2. Type a name for the hive that you've loaded now. (Example: MyXPHive)
  3. Now the SOFTWARE hive is loaded, and present under the HKEY_USERS base hive.
  4. In order to fix the Userinit value in the loaded hive, navigate to the following location:
HKEY_USERS \ MyXPHive \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
  1. Double-click Userinit and set it's value correctly. Example: Set it's data as follows:
C:\Windows\System32\Userinit.exe,
(Include the trailing comma also. The above assumes that Windows is installed in C:\Windows, and Userinit.exe file is actually present in the System32 folder. You may want to verify that as well.)
  1. After entering the correct data, you MUST unload the Hive. To do so, select MyXPHive branch, and then in the File menu, choose Unload Hive. It's important to note that you'll need to select the MyXPHive branch first, before unloading it.
  2. Quit BartPE and restart Windows. See if you're able to logon to your profile.

Tidak ada komentar:

Posting Komentar