1. Cause: Because viruses, Spyware, Troyand edit or delete entries in the Userinit registry at HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
. 2. Handling:
.
* First you try to scan and kill virus before. You can use the boot from Dos to scan (in Hiren's boot disk scanning programs, should Mcafree to scan first, then scan again with F-Prot) or remove the hard drive attached to another machine to scan.
* Search for the right to edit Regitry:
.
Right in the registry that is:
.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
.
Userinit entry is as follows
.
Value: Userinit
.
Data:% Windir% \ System32 \ Userinit. exe,. Where% Windir% \ is a directory of your installation Winodws. Usually C: \ Windows \ System32 \ Userinit. exe,
.
Please note: a sign, at the end.
In case of lost deleted virus called Userinit string, you automatically regenerate another by: right click, select New-> String Value. Change its name into Userinit, and then Double Click on it and type the correct path to the Userinit. exe in the Value data nhé. For example usually as follows:
.
C: \ Windows \ System32 \ Userinit. exe,
.
3. By adding Regitry from DOS:
.
There are many ways to edit the registry from DOS use the Hiren's BootCD, WinBuilder, Bart's PE Builder, miniPE ... In short how to use even more of our primary purpose is to edit the Registry is
. Left to right above.
In this article I guide you to manipulate with the rescue was made from Bart's PE Builder (eg PE Windows XP, Windows Server 2003-foot limit).
PE booting from your disk, interface as follows:
.
Choose Go -> Run -> and type Regedit to open Registry
.
However, this is a Registry Registry of PE (the windows on the CD, not the machine you need to edit). So, to fix the computer registry, you must carry load.
In Registry Editor, click on the branch you need to edit and click on the File menu \ Load hive and then choose File representing combinations to edit the Registry Software, Sam, Security ... the combination is usually located in C: \ Windows \ System32 \ Config
.
For example, in this case we need to change the HKEY_LOCAL_MACHINE branch is selected, then the menu File -> Load Hive
.
Look in you in the path to: C: \ Windows \ System32 \ Config. We need to edit the Registry should we choose Software Software and click Open. The system will ask what is Key Name: This is not important, what you put also. List examples. Then in HKEY_LOCAL_MACHINE will have a new category called KeyName you've set. This corresponds to the Software section on the need to correct. You here to conduct the Registry right back to the above mentioned.
After you complete Click the Load Lock her up and then emerged at the File menu, choose to remove Hive unload.
Then you reboot and run windows on your machine. Phenomenon "to then strike out" is no longer available.