I had some malware which was cleaned. It was hooked onto smss32 and winlogon i think. I'm unable to boot into windows using safemode. I try the last known good config, wont do it. I think I have to get into the registry and edit a part where it points to userinit.exe
But how can I access the registry if I cannot boot into windows? Is there just a way where i can restore to a registry backup?
Dang, you can't even boot into "Safe Mode"? I don't know of any options besides a complete reformat.
If you still have the xp cd's you can do a non destructive repair install.
I have the xp cd. Will I lose any of my data or saved settings if i do that? Repair instead of Recovery?
Also, would it be easier to use a LiveCD?
Just try the XP disc, saves time than booting it into Live and reparing it.
BTW, what malware did you had?
I think that is it because those files were the ones I deleted. It's called "Netsky" I guess
Well I pressed R to get to the recover console, not exactly sure what to do now. I tried to do the copy userinit.exe thing, but that didn't work. I don't even know if I can repair because its an OEM disk.
also loaded up a linux livecd to see if i can find a way to fix it.. nothing. I did however notice a partition called HP Recovery. It was originally an HP, but I did a reinstall of xp pro instead of xp home which came with it.
still loads to welcome screen, then i can see my wallpaper, then back to the logon screen.
is there a way i can repair the winlogon? or is there a way i can some how access the system restore points via livecd or something?
n/m... i think i got it.
I used ERD 5.0 to get to a restore point
This will explain the repair option you need in better detail:
Quote:The "Welcome to Setup" screen is poorly worded; the "Repair" option we want isn't the one explicitly offered here. In fact, the repair option we want isn't shown at all. [Press ENTER]

[F8-I Agree]
[Searching for previous versions of windows...]
At long last, Setup begins to refer to a Repair option. Here, Setup should have found your damaged XP setup, which you can select and then press R to start the nondestructive repair. [Press R]

http://www.informationweek.com/1094/langa02.jhtml;jsessionid=DACPGHCJORTWPQE1GHOSKHWATMY32JVN
Copyright 2013 © Godem Online Inc. | Web and server solutions by NewTech Solutions.