How can I stop my pc from rebooting after removing smart hdd virus and doing system restore on a xp pro machine.

Posted on 2012-08-23
Last Modified: 2012-08-27
HDD VIrus made everything dissapear. I followed instruction on how to remove it.

After i regained control, i did the unhide.exe also. I got programs back
but they all said empty.

So i tried the easy system restore.OOPS
NOw pc keeps rebooting.
I have a XP home disc.
OS im working with is XP PRO
Also tried a repair utility booting from cd and entering in certain commands in command line but that did not work either
I could not get past the first line. I could only enter in one letter.
I extracted all files from all user onto a external hard drive but I want the machine running again. I took the hard drive out and used a Ultradock v4 for sata and ide drives.
I dont have any OEM's for the xp home that I want to give away any away. the OEM code is not on the side of box for XP PRO.
I can also scan the Hard drive with ESET antivirus too.
WHat NEXT anybody???
I will be putting the hdd back in tomorrow but its kinda hard to troubleshoot anything when the pc keeps rebooting!
ANY HELP would be greatly appreciated
Question by:Gerbz
    LVL 46

    Expert Comment

    Since you have no way of knowing the extent of the damage when you are booted, you are going to have to get another HDD, (or a large USB flash drive), and install the O/S to that.

    Then you can assess the damage.  If you don't have another computer you can transfer the files to for safe keeping over the network, then you're just going to have to purchase another HDD.

    THere really is no other way to know exactly what is going on if you are booted to the infected system.
    LVL 46

    Expert Comment

    If you do have to purchase another HDD, then you can later use it for an external backup drive, or turn your system into a dual-drive RAID1 config, which will protect against data loss in event of a drive failure.   It won't help you with data loss in event of a virus.
    LVL 3

    Expert Comment

    I guess the way to go is to do a clean reinstall.Even u manage to get it working u will have a lot of issues due to severity of the damage.
    LVL 91

    Expert Comment

    i agree a fresh install maybe the best, but if you  want, you can try this method for a system restore  (and pick an older one)
    An easier way is to boot from a Bart PE CD (or UBCD4Win CD) and use the file manager for manipulating files. Here  the procedure :
    1. rename c:\windows\system32\config\SYSTEM to c:\windows\system32\config\SYSTEM.bak
    2. Navigate to the System Volume Information folder.
    it contains some restore {GUID} folders such as "_restore{87BD3667-3246-476B-923F-F86E30B3E7F8}".
    The restore points are in  folders starting with "RPx under this folder.
    3. In such a folder, locate a Snapshot subfolder. This is an example of a folder path to the Snapshot folder:  C:\System Volume Information\_restore{D86480E3-73EF-47BC-A0EB-A81BE6EE3ED8}\RP1\Snapshot
    4. From the Snapshot folder, copy the following file to the c:\windows\system32\config folder
    6. Exit Bart PE, reboot and test

    Use a fairly recent restore point from at least a day or two prior to problem occurring .

    ** you can add the other hives also with this procedure       BARTPE            UBCD4WIN
    LVL 6

    Expert Comment

    What you can do as well is try and get a Windows XP SP3 disc from someone and try a windows repair it is the second repair option that comes up before you can delete the partition, as the XP home edition will not work so i think everything you have tried with the XP home disc was a wast of time.
    LVL 16

    Accepted Solution

    A system repair and a system restore will most likely not work as viruses often attach themselves to restore points. You need to do a clean install. For this you will first need to extract the windows cd key. Use this free program:

    Once you have the key, you must obtain an OEM Windows XP Pro disk (if this is the OS currently on the computer). Boot with the cd and do a clean install. Restore user data and you are done.
    LVL 6

    Expert Comment

    I suggested the windows repair to see if he can get into his desktop to retrieve that licence key as he stated that he does not have a OEM Sticker on the box and the PC keeps rebooting so there is no way he can get into his desktop at the moment.
    LVL 30

    Expert Comment

    Knowing why it is rebooting would help. Using F8 to get to the boot options screen, disable automatic restart. This should result in a blue screen with an error message. We can then go from there. I would tend to agree with nobus that it is a corrupt registry hive, but know ing for certain, and knowing which one, would really help.

    Author Closing Comment

    I have not had time to use these solution yet but thanks for the input. I think magic jellybean will do the trick though if I can extract the OEM

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
    For both online and offline retail, the cross-channel business is the most recent pattern in the B2C trade space.
    The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.
    The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now