THIS SOLUTION WORKS 100%
Let me explain what happen with ur computer (why u cant login into ur windows account).
1) u got a virus
2) it copied itslef, or it made a copy simmilar name to itself into ur WINDOWS/system32
3) it cahnged the registry key: HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon, and instead "Userinit.exe", it wrote its name
So, heres an example:
1) u got a virus, for an example, "winupdate86.exe"
2) it made a copy inside system32 as "winlogon86.exe"
3) changed registry key, and in entry putted "winlogon86.exe"
So, ur computer actualy loged on via virus, all time until ur antivirus deleted it (after that u couldnt be able to login). After ur antivurs detected and removed the virus( both "winupdate86.exe" and "winlogon86.exe") ur windows continues to look for "winlogon86.exe", couse it is on current place in registry,and its all it knowsto look for, when it try to login.
So, to solve the problem u need to (SOLUTION!!!)
1) only way to recover ur login is to find a copy of "userinit.exe" file (from XP DVD, from another computer...)
2) rename it to be as name of virus u had (u maybe dont know it, couse ur antivirus deleted it, but if u know u llbe able to fix ur login). So, sopy of "userinit.exe" rename to "winlogon86.exe"
3) put new renamed copy into ur system32 (Ofc, u dont have windows on ur computer, couse u cant login, but ucan plug off hard disk and plugin it to another computer. Other solution is if u can make bottable USB or Floppy disk DOS, and use simple copy function. 3th solution is if u have another operative system on ur computer, and manage coping there)
4) login ur windows normaly (now after u tricked ur regystry key, it still looks for same entry when it login, which was name of virus. But trick is u made a copy of real userinit.exe, and renamed to trick registry)
5) find via regedit HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ , and instead name of virus, put "userinit.exe"
Thats all, ofc if u still have virus would be great if u write its name before ur Antivirus delete.. If u still know it, just do steps. If u dont know actual name of virus u can do steps, but not gonna help u. Couse u need to know whats written in entry HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ . I found alctual name of my antivirus in way I go to search files inside my WINDOWS folder. And after it finished, I sorted all files with Modified Date, and Created Date... I found all files of virus in my system32... Deleted them and I had this problem... but after I saw all u people worte here I knew how to fix. Ofc I was lucky cuz I before deleting them, made a carantine. So I knew names. And with another comuter fixed.
No comments:
Post a Comment