[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How can I stop my pc from rebooting after removing smart hdd virus and doing system restore on a xp pro machine.

Posted on 2012-08-23
9
Medium Priority
?
655 Views
Last Modified: 2012-08-27
HDD VIrus made everything dissapear. I followed instruction on how to remove it.

http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd

After i regained control, i did the unhide.exe also. I got programs back
but they all said empty.

So i tried the easy system restore.OOPS
NOw pc keeps rebooting.
I have a XP home disc.
OS im working with is XP PRO
Also tried a repair utility booting from cd and entering in certain commands in command line but that did not work either
I could not get past the first line. I could only enter in one letter.
I extracted all files from all user onto a external hard drive but I want the machine running again. I took the hard drive out and used a Ultradock v4 for sata and ide drives.
I dont have any OEM's for the xp home that I want to give away any away. the OEM code is not on the side of box for XP PRO.
I can also scan the Hard drive with ESET antivirus too.
WHat NEXT anybody???
I will be putting the hdd back in tomorrow but its kinda hard to troubleshoot anything when the pc keeps rebooting!
ANY HELP would be greatly appreciated
0
Comment
Question by:Gerbz
9 Comments
 
LVL 47

Expert Comment

by:David
ID: 38327845
Since you have no way of knowing the extent of the damage when you are booted, you are going to have to get another HDD, (or a large USB flash drive), and install the O/S to that.

Then you can assess the damage.  If you don't have another computer you can transfer the files to for safe keeping over the network, then you're just going to have to purchase another HDD.

THere really is no other way to know exactly what is going on if you are booted to the infected system.
0
 
LVL 47

Expert Comment

by:David
ID: 38327847
If you do have to purchase another HDD, then you can later use it for an external backup drive, or turn your system into a dual-drive RAID1 config, which will protect against data loss in event of a drive failure.   It won't help you with data loss in event of a virus.
0
 
LVL 3

Expert Comment

by:masteripper
ID: 38328023
I guess the way to go is to do a clean reinstall.Even u manage to get it working u will have a lot of issues due to severity of the damage.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 93

Expert Comment

by:nobus
ID: 38328170
i agree a fresh install maybe the best, but if you  want, you can try this method for a system restore  (and pick an older one)
http://support.microsoft.com/kb/307545
----------------------------------------------------------------------------------------------
An easier way is to boot from a Bart PE CD (or UBCD4Win CD) and use the file manager for manipulating files. Here  the procedure :
1. rename c:\windows\system32\config\SYSTEM to c:\windows\system32\config\SYSTEM.bak
2. Navigate to the System Volume Information folder.
it contains some restore {GUID} folders such as "_restore{87BD3667-3246-476B-923F-F86E30B3E7F8}".
The restore points are in  folders starting with "RPx under this folder.
3. In such a folder, locate a Snapshot subfolder. This is an example of a folder path to the Snapshot folder:  C:\System Volume Information\_restore{D86480E3-73EF-47BC-A0EB-A81BE6EE3ED8}\RP1\Snapshot
4. From the Snapshot folder, copy the following file to the c:\windows\system32\config folder
 _REGISTRY_MACHINE_SYSTEM
5. Rename _REGISTRY_MACHINE_SYSTEM to SYSTEM
6. Exit Bart PE, reboot and test

Use a fairly recent restore point from at least a day or two prior to problem occurring .

** you can add the other hives also with this procedure

http://www.nu2.nu/pebuilder/       BARTPE
http://www.ubcd4win.com/            UBCD4WIN
0
 
LVL 6

Expert Comment

by:Kyle Davies
ID: 38328380
What you can do as well is try and get a Windows XP SP3 disc from someone and try a windows repair it is the second repair option that comes up before you can delete the partition, as the XP home edition will not work so i think everything you have tried with the XP home disc was a wast of time.
0
 
LVL 16

Accepted Solution

by:
rbudj earned 2000 total points
ID: 38329211
A system repair and a system restore will most likely not work as viruses often attach themselves to restore points. You need to do a clean install. For this you will first need to extract the windows cd key. Use this free program: http://www.magicaljellybean.com/keyfinder/

Once you have the key, you must obtain an OEM Windows XP Pro disk (if this is the OS currently on the computer). Boot with the cd and do a clean install. Restore user data and you are done.
0
 
LVL 6

Expert Comment

by:Kyle Davies
ID: 38329248
I suggested the windows repair to see if he can get into his desktop to retrieve that licence key as he stated that he does not have a OEM Sticker on the box and the PC keeps rebooting so there is no way he can get into his desktop at the moment.
0
 
LVL 30

Expert Comment

by:flubbster
ID: 38329304
Knowing why it is rebooting would help. Using F8 to get to the boot options screen, disable automatic restart. This should result in a blue screen with an error message. We can then go from there. I would tend to agree with nobus that it is a corrupt registry hive, but know ing for certain, and knowing which one, would really help.
0
 

Author Closing Comment

by:Gerbz
ID: 38338930
I have not had time to use these solution yet but thanks for the input. I think magic jellybean will do the trick though if I can extract the OEM
0

Featured Post

Upgrade your Question Security!

Add Premium security features to your question to ensure its privacy or anonymity. Learn more about your ability to control Question Security today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Suggested Courses

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question