Forum Home
Press F1
 
Thread ID: 86855 2008-01-30 19:41:00 local policy does not permit you to logon interactively pctek (84) Press F1
Post ID Timestamp Content User
635590 2008-01-30 19:41:00 WinXP Home OEM

Never had a password, never was set to use the Click on username to enter Windows.

Not networked.

I suspect malware but how do I get into the thing? Its on all accounts including Administrator.
pctek (84)
635591 2008-01-30 20:01:00 Try hitting CTRL+ALT+DEL twice at the login screen; this will give you the alternative 'standard' login shell. If this lets you log in (it probably will), then fire up the group policy editor and remove the restriction on the 'welcome screen' login shell.

If that still fails, try booting it with BartPE and doing an offline registry edit. This is a pain in the ass though, the above method is much easier.
Erayd (23)
635592 2008-01-30 20:11:00 Nope, no login works.

To make matters more exciting its one of those sata drives that needs a driver off the floppy before Windows sees it.

So my ERD Commander 2002 doesn't see it either.
pctek (84)
635593 2008-01-30 20:13:00 Have you tried BartPE? That will accept driver floppies during boot. Erayd (23)
635594 2008-01-30 20:18:00 Ouch - if ERD locks you out - this here Ophcrack (http://ophcrack.sourceforge.net/) - it runs off a bootable CD, (455Mb ISO file)and it may tell you what the passwords are. Can take a while sometimes.

Updated: Just found This article (www.raymond.cc) Never tried it, but worth a crack if it works. ( #10 onwards is of interest)
wainuitech (129)
635595 2008-01-30 21:12:00 Dont know if the above works, BUT if you are able to boot into safe mode with command prompt, and type NUSRMGR.CPL

Hopefully if its malware it wont be running in safe mode and allow you in.

This open the user accounts, you may be able to remove or at least alter passwords. (just tried it and it worked fine on a healthy machine)
wainuitech (129)
635596 2008-01-30 22:40:00 Ok, I admit defeat.

The Shift F10 during repair sounded promising.
But it says no user accounts recognised.

BartPE allowed reg editing but nope, the thing is knackered.

I admit defeat and shall wipe it.
pctek (84)
635597 2008-01-30 22:51:00 Before you wipe it, try restoring the HKLM hive backup. It can't hurt and just might fix it, although I admit your chances are pretty low. Erayd (23)
635598 2008-01-31 00:57:00 Customer has decided he'll wipe it himself. pctek (84)
635599 2008-01-31 01:00:00 Customer has decided he'll wipe it himself.

And come back to see you next week wondering why nothings working and his display resolution is 640x480.
wratterus (105)
1 2