Found virus Changing boot, editng regristry reverts back

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TheSillyBilly, Jan 24, 2010.

  1. TheSillyBilly

    TheSillyBilly Private E-2

    Hey forums, Well after 3 years of virus free, I got one, only problem is, I cant woop it. I am an advanced user, and I have repaired many machines except the one I really need. I followed the steps for removal on the sight and it cleaned a lot of it out, at least I am able to log on and got my speed back. Problem is, found a few things still not wanting to work like my virus protection, sfc /scannow, Disk manager, windows update, ect,,, all the things one needs to be safe. I can edit the registry without denies, but I can watch as it reverts back to where it was set. Also one of the virus removals, I can set it up to scan like I want it to, and as its scanning, the settings or being changed, it is being controlled from within. My main thing is, the line in my registry reading, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup and the string BootDir is set to c:\ which is normally default, but mine is E:\, there is NTLDR and boot.ini and all the files on the C: to boot just like on my E: which is where the OS is. So I was like,,,"ok, I will just unplug all extra drives and lets see what ya got?" Well, at boot is says the NTLDR is missing or corrupted..... Please help???
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Insert the Windows XP bootable CD into the computer.
    2. When prompted to press any key to boot from the CD, press any key.
    3. Once in the Windows XP setup menu press the "R" key to repair Windows.
    4. Log into your Windows installation by pressing the "1" key and pressing enter.
    5. You will then be prompted for your administrator password, enter that password.
    6. Copy the below two files to the root directory of the primary hard disk. In the below example we are copying these files from the CD-ROM drive letter, which in this case is "e." This letter may be different on your computer.

    copy e:\i386\ntldr c:\
    copy e:\i386\ntdetect.com c:\

    7. Once both of these files have been successfully copied, remove the CD from the computer and reboot.


    Now if you can boot up:

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds