XP logs out immediately after loggin in!!

S

sombre1

Folks,
I have somehow managed to set a security policy that will not met me
log in normally. When I try the system logs me out immediately. I can
however, log in in safe mode and I found the following event in the
event viewer.

Access to C:\\Windows\system32\userinit.exe has been restriced by
the administrator with policy {191cd7fa-f240-4a17-8986-94d480a6c8ca}

Anybody know who to restore this policy?
 
R

Ramesh, MS-MVP

It looks like you've locked yourself out by setting a Path rule in Software
Restriction Policy settings. To unblock userinit.exe (a vital file, without
which user logon is not possible).

My suggestion is to edit the registry offline, using BartPE boot CD. Copy
userinit.exe (C:\Windows\System32 folder) to newuserinit.exe. Then, change
the "userinit" registry value to "newuserinit.exe". Then restart the system,
and attempt to logon as Administrator. Undo the Policy settings which you've
misconfigured earlier.

If all goes well, then change the userinit value back.

Example:

How to edit the registry offline using BartPE boot CD ?:
http://windowsxp.mvps.org/peboot.htm

--
Regards,

Ramesh Srinivasan, Microsoft MVP [Windows XP Shell/User]
Windows® XP Troubleshooting http://www.winhelponline.com


Folks,
I have somehow managed to set a security policy that will not met me
log in normally. When I try the system logs me out immediately. I can
however, log in in safe mode and I found the following event in the
event viewer.

Access to C:\\Windows\system32\userinit.exe has been restriced by
the administrator with policy {191cd7fa-f240-4a17-8986-94d480a6c8ca}

Anybody know who to restore this policy?

--
Posted at author's request, using http://www.WinForumz.com interface
Articles individually verified to usenet standards. Visit URL to contact
author/report abuse
Thread archive:
http://www.WinForumz.com/windows/XP-logs-loggin-ftopict532113.html
 
S

sombre1

Hi Ramesh,

Thank you for this, however, I am able to logon as the Administrator in
safe mode, I just can't remember what I changed to prohibit logging in
normaly.
I have checked the registry C:\Windows\System32\Userinit.exe, and it
all looks fine.
THe problem is a security setting that will not allow windows to launch
this file.

Looking in 'Local Security Policy' all looks OK here with no
restrictions. None-the-less, I find Policy
{191cd7fa-f240-4a17-8986-94d480a6c8ca} in the 'Event Viewer' as set by
the administrator (me) won't allow userinint.exe to run.

I can also find this policy in the registry, do youthink I should
simply delete the policy folder?

I find this folder in the registry by running regedit in the command
line then my computer > HKEY_LOCAL_MACHINE > software > policies >
Windows > safer > code identifiers > paths >
{191cd7fa-f240-4a17-8986-94d480a6c8ca}.
When I open this registery I see the following:

Name Type Data
(default) REG_SZ (value not set)
Descritpion REG_SZ
ItemData REG_Z EXPAND_SZ
%key_local_machine\software\microsoft\Wind...
SaferFlags REG_DWORD 0x000000000(0)

Should I delete this whole thing of change a value somewhere?
David
 
R

Ramesh, MS-MVP

David,

Was the system connected to a domain recently?

Yes, I think so. But, it's safe to have appropriate backups of the registry
(all hives), using ERUNT.


[ERUNT] Registry Backup and Restore for Windows
http://www.larshederer.homepage.t-online.de/erunt/

[ERUNT Download URLs]
http://www.aumha.org/downloads/erunt.zip
http://www.aumha.org/downloads/erunt-setup.exe

[Installing & Using ERUNT]
http://www.winxptutor.com/regback.htm
http://www.silentrunners.org/sr_eruntuse.html
http://www.larshederer.homepage.t-online.de/erunt/erunt.txt


--
Regards,

Ramesh Srinivasan, Microsoft MVP [Windows XP Shell/User]
Windows® XP Troubleshooting http://www.winhelponline.com



Hi Ramesh,

Thank you for this, however, I am able to logon as the Administrator in
safe mode, I just can't remember what I changed to prohibit logging in
normaly.
I have checked the registry C:\Windows\System32\Userinit.exe, and it
all looks fine.
THe problem is a security setting that will not allow windows to launch
this file.

Looking in 'Local Security Policy' all looks OK here with no
restrictions. None-the-less, I find Policy
{191cd7fa-f240-4a17-8986-94d480a6c8ca} in the 'Event Viewer' as set by
the administrator (me) won't allow userinint.exe to run.

I can also find this policy in the registry, do youthink I should
simply delete the policy folder?

I find this folder in the registry by running regedit in the command
line then my computer > HKEY_LOCAL_MACHINE > software > policies >
Windows > safer > code identifiers > paths >
{191cd7fa-f240-4a17-8986-94d480a6c8ca}.
When I open this registery I see the following:

Name Type Data
(default) REG_SZ (value not set)
Descritpion REG_SZ
ItemData REG_Z EXPAND_SZ
%key_local_machine\software\microsoft\Wind...
SaferFlags REG_DWORD 0x000000000(0)

Should I delete this whole thing of change a value somewhere?
David
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top