Hi there,
First a situation sketch:
The last few days I've been struck my a malicious trojan horse. After I
deleted it with Kaspersky Anti-virus software, it (during the the scan)
rebooted my Pc out of the blue (without any notification or warning).
From then on I've been unable to login to windows (it's stuck on the welcome
screen, when pressing my account it says that's it's loading my preferences
etc... but it immediatly logs me off again leaving me no other option then to
turn off my PC).
I searched the web intensively to see what my problem was. I've tried the
sollution suggested by microsoft to copy userinit.exe as wsaupdater.exe
(problem with Lavasoft after removing the blazefind virus) in the recovery
console using my recovery CD.
Now the "possible" solution sketch:
Not to my surprise that didn't work (I haven't been struck by this
particular virus). Out of ideas I decided to buy and install a program called
"ERD commander"
(
http://www.winternals.com/Products/A...k/Default.aspx) that
let's you boot death system etc... It's a nifty program.
I used this program too check the registry to see what was wrong with my
winlogon regirstry keys. To my surprise nothing was wrong with the userinit
in the follow ingregistry key:
HKLM\Software\Microsoft\windows NT\CurrentVersion\Winlogon\
the value is right (I think): %SystemRoot%\System32\userinit.exe,
The only odd thing is that, compared to my working D Windows version (I
installed a new Windows version to my D partition) , the type of the registry
key is REG_EXPAND_SZ compared to REG_SZ (D: windows version)
Is this a problem?
But the real problem (at least I think it is) is that the value of the
"Shell" key in
HKLM\Software\Microsoft\windows NT\CurrentVersion\Winlogon\
reads as "explorer.exe 1" compared to "explorer.exe" on my working D: version.
Am I on the right track to assume that here in lies my problem i.e. changing
the value from "explorer.exe 1" to "explorer.exe" should fix my login problem.
If not, could you provide me with another possible sollution (for example
checking other registry keys that deal with the loging to windows)?
Once again sorry for my long post (I'm not a native english speaker) but I
wanted to sketch my situation as comprehensibly as possible
Thanks in advance,
Tobin