Up All Nite - this has been a tough one!

Discussion in 'Malware Help (A Specialist Will Reply)' started by RJHollins, Jun 12, 2010.

  1. RJHollins

    RJHollins Private E-2

    Hello Gentleman,

    Wow ... what a battle going on with my system.

    About 4 weeks ago, I was hit with a fake ANTI-Virus screen [ave I believe],
    and thought I had taken steps to properly remove it ... but things got slowly worst.

    I have scanned & rescanned numerous times ... finding 2 or 3 registry keys
    that where flagged and removed. Still the computer was not right.

    I have NO pop-ups ... and there have been NO error messages ... but I still
    ran a SFC /scannow ... nothing semed to change.

    I do get ONE error message when I start up:

    INVALID BOOT.INI

    but then Windows will proceed to load [whether in SAFE mode or Normal] mode.

    Coming back to MajorGeeks [had to use your services years ago on another computer], I tried to get all the prepatory log files ... although I did have problems with lock-ups. In fact ... that is what's been happening with this computer.

    As a next major step, I went on to run COMBOFIX.
    It tried to install the 'Recovery Console', but reported an error [probably due to the Boot.ini issue] ... but then went on to scan. It found a rootkit ... then re-booted itself ... and then continued with the scan ... posting a log file in C:\ .

    Which is what bring me here .... I need YOU !!!!!

    Concurrently ... another issue has been going on.

    My harddrive LED has been writing ALOT ... and I now have 2 instances of something called 'HELPASSISTANT' in my doc folder. I tried to turn these off and delete ... but they return. This is not normal for this computer. And these folders are HUGE ... some 40k+ files nearly 1-2 gigs.

    At this point ... I wanted to post what logs I have and await guidance before proceeding ahead. [as I know just enough about computers to be dangerous] :)

    Thank-you ... and await your reply.

    Sincerely,

    RJHollins
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You likely have a master boot record infection. You need to do all of the below.



    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop
    • Double click HelpAsst_mebroot_fix.exe to run it and follow any prompts.
      • If the tool detects an mbr infection
        • please allow it to run mbr -f and shutdown your computer.
        • Upon restarting, please wait about 5 minutes after bootup, and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
      • If the tool DOES NOT detect an mbr infection and completes running:
        • Click Start>Run and type the following bolded command, then hit Enter.
          • mbr -f
        • Make sure you leave a space between mbr and the -f
        • Now, please do the Start>Run>mbr -f command a second time.
        • Now shut down the computer (do not restart, you must shut it down), wait a few minutes then start it back up.
        • Give it about 5 minutes after the bootup and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
    **Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).

    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!


    Please follow the instructions in the below link:


    READ & RUN ME FIRST. Malware Removal Guide


    Also see the notes at the end of this sticky:Forum Rules and Guidelines which will explain why your message was trapped in the spam filters. That is, you need to stop using ... or similar.
     
  3. RJHollins

    RJHollins Private E-2

    Hello chaslang,

    First ... thank-you for handling my case :)

    OK ... I ran the 'HelpAsst_mebroot_fix' file that you posted ...

    It DID detect an mbr infection.
    Ran it according to your instructions.
    After shutdown ... then restarted ... waited 5+min and then
    CommandPrompt 'helpasst -mbrt'

    That command executed in about 1 second ... and posted a log [which I
    have attached.

    I understand this is early ... but just to notify of what I see ...

    The computer is responding much faster ... but ...

    When I first boot ... the INVALID BOOT.INI still shows before WINDOWS
    launches.

    Also ... all IE associations seem to be changed as they do not have the
    IE icon reference ... and ALL 'bookmarks' have changed icons and do NOT
    respond in IE.

    Anyway ... just wanted to mention this observation.

    OK ... so I will now attempt to run the instructions in the last half of your
    post "READ & RUN ME FIRST" and try to get new logs.

    I'll check emails via my iPhone during this :)

    Again ... thank-you for your guidance !!!!

    Sincerely,

    RJHollins
     

    Attached Files:

  4. RJHollins

    RJHollins Private E-2

    Hi chaslang,

    hmm ... something I should have noticed/remembered ... sorry :(

    Looking at the HelpAsst log file ... and then I went to the Documents &
    Settings folder on C:\ and noticed that the folder called:

    'HelpAssistant.RJHQ9450-kill this' is still there ... and I think I know why ...

    I had thought I disabled this in the 'My Computer' ... MANAGE ... USER group
    section ... and thought I could just delete the 'HelpAssistant.RJHQ9450' folder. When I couldn't, I found that I could RE-NAME it ... so I did:

    to 'HelpAssistant.RJHQ9450-kill this'

    I thought after a Re-Boot ... the folder might be released so I could delete it ... no can do.

    I forgot to name it back to its original name 'HelpAssistant.RJHQ9450' before
    running the HelpAsst_mebroot_fix.exe' file.

    I would think we want this one deleted too ... before I try to run any other
    cleaning programs.

    Big apologies for messing us up like that ...

    I will wait to hear from you BEFORE I do anything else.

    Thank-you for your understanding !!!

    Sincerely,

    RJHollins
     
  5. RJHollins

    RJHollins Private E-2

    hmmm ... no way to edit previous post ?!?

    Another 'item' ....

    When COMBOFIX was first ran ... the 'Repair Console' did NOT install.

    Just wanted to keep you informed of the current status.

    Apologies for the multiple posting ...

    RJHollins
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everytime you post, you bump your thread and cause additional delay in getting an answer. See:Don't Bump! It Only Hurts You!!!

    We can see that the Recovery Console was not installed via your logs.

    No! You needed to continue with my instructions as we need those additional logs to continue.
     
  7. RJHollins

    RJHollins Private E-2

    Hi chaslang,

    Here are the attached log files from my recent scans.

    There was an issue with SUPERAntiSpyware ... I had to download the 'portable' version in order to run it.
    It completed the scan, found 11 .dll files suspected ... it then deleted them,
    then RE-BOOT. When I re-ran SUPER [in order to get the log files, as instructed, the Stat/log section was blank. :|
    I looked for a log in SUPER's folder ... not there ... nor in the C:\ root.

    So I've included all the logs that I now have.

    Awaiting your further instructions ... and again, THANK-YOU :)

    Sincerely,

    RJHollins
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs you have Avast and SpywareDoctor with AntiVirus installed. Is this correct? Is SpywareDoctor a paid program or a free trial progam?

    I also see that you have SUPERAntiSpyware Professional which is a paid program and I don't recommend having this and Spyware Doctor installed at the same time.

    You need to uninstall Spybot - Search & Destroy 1.4 which is the old outdated program version.

    Did you remember to click the Accept button for HijackThis when you ran MGtools or did you not see it? The log was not created. Be on the look out for it when doing the below.

    What is the below startup process you are loading?
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "KRun"="c:\runme\RunMe.exe" [2008-04-16 1299968]


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. RJHollins

    RJHollins Private E-2

    Hi chaslang,

    To the questions you asked:

    1. I use Avast. The SpywareDoctor was a trial I installed.
    2. SUPERAntiSpyPro is also something I use.
    3. I've NOW un-installed SpywareDoctor.

    4. Spybot 1.4 is now UN-installed ... I guess I should go to the latest version.

    5. 'Accept button for HiJackThis' ... I thought I did.

    For this last scan with MGTools I DEFINITELY did accept ... however, I received an error message ... something wrong there :|

    You asked about RunMe.exe ... [i know, that is a very suspecious name] but it is a Program Launcher Toolbar that floats offscreen. The website is: www.ksoft.nm.ru it is a free utility [hope nothing is wrong about it cause it is quite handy.
    ------------

    As per your instructions, I pasted the script to CFscript.txt ... following step by step the drag/drop to Combofix. The log file is attached.

    Then ... ran MGTools ... accepted HiJackThis ... which posted an error [hope that is included in the logs].

    OK

    How things are working?

    Well ... definite improvement ... but a few issues.

    1. Still the 'INVALID Boot.ini' message when I start up ... yet Windows still launches.

    2. The massive 'HelpAssistant.RJHQ9450-kill this' is still there. This is the folder that I had renamed [added the '-kill this'] all before contacting you at MajorGeeks.

    3. In IE, it seems all my bookmarks are inactive, and all website shortcuts on the desktop have also lost their 'association'.


    These are the few issues I've noticed ... but I must relay that the computer has not crashed or lockedup like before.
    I was able to run SUPERAntiSpy [the portable version] and it reported a clean scan [still can't find a saved log for that ... but a complete full scan came up clean :) got to be happy bout that !!

    Anyway ... let me get these logs up to you, and look forward to your next instructions.

    Sincerely, and THANK-YOU !

    RJHollins
    [Up All Nite Mastering Studios]
     

    Attached Files:

    Last edited by a moderator: Jun 15, 2010
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good because that was what I was going to have you do next. ;) If Registry Mechanic came with it ( and I assume it did ) you should uninstall it too.

    You already had 1.6.2 installed. I only asked you to uninstall the 1.4 version but you uninstalled both and will have to reinstall the current version later. You can get it here: SpyBot-Search & Destroy

    That's because your boot.ini file appears to be missing based on your logs.

    My last fix was supposed to delete this folder, but it does not look like it deleted. Can you delete it manually?

    Your file association for HTML files may have been broken. Go here:http://www.dougknox.com/ and download and run the fix for HTM/HTML files.


    Why can't you run a scan with the Pro version you have installed.
     
  11. RJHollins

    RJHollins Private E-2

    "If Registry Mechanic came with it ( and I assume it did ) you should uninstall it too."

    Reg Mechanic was a separate install. It's an older version. I only used it from time to time ... but since changing wincfg to 'normal startup', it is loading at boot-up. I'd prefer it not to autoload ... not sure how to do that ... that is unless there is some issue with this app that you recomend removing it ?



    " You already had 1.6.2 installed. I only asked you to uninstall the 1.4 version but you uninstalled both and will have to reinstall the current version later. "

    Thanks for the link ... 1.6.2 now installed.



    "That's because your boot.ini file appears to be missing based on your logs."

    I see the BOOT.INI file is in the root C:\ directory, but I think it is 'blank'. Can I replace this file? or edit it ? As you probably know, WINDOWS is installed in the 'standard' location on my 1st primary drive [followed by 5 more harddrives and a SATA CD/DVD burner.


    "My last fix was supposed to delete this folder, but it does not look like it deleted. Can you delete it manually?"

    I was able to 're-name' the folder to its original name [removing the "-kill this" that I added] ... once I did that, I was able to delete the folder & content. BTW, that was one massive folder :|


    " Your file association for HTML files may have been broken. Go here and download and run the fix for HTM/HTML files."


    OK ... grabbed the .reg file from this site, dbl-clicked & added it to the registry. Even after a re-boot, still bookmarks are not working :(


    " Why can't you run a scan with the Pro version you have installed."

    The PRO version was locking up when checking for updates ... I will try a re-install.


    OK ... wanted to get this info back to you ... awaiting further instructions!

    Thank-you

    RJHollins
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the below which explains how to use the bootcfg command to rebuild the file properly. This needs to be run from the Recovery Console.

    "Invalid Boot.ini" or "Windows could not start" error messages ...


    What exactly do you mean by "bookmarks are not working? Do the ones in your Favorites work? Give an example (by name) of a file on your desktop that is not working. I'm guess that what you may mean is the URL's are not working and that you need the below fix instead of the HTML fix:

    URL File Association Fix

    Did that help?
     
    Last edited: Jun 17, 2010
  13. RJHollins

    RJHollins Private E-2

    Did not help :( Added to the register ... even re-booted .. no change.

    The 'bookmarks' in IE 'Favorites' do not work ... clicking on them does nothing.
    In the 'Favorites' sidebar menu, all of the icons have a 'generic' look ... like they are not assigned to any app.

    On the desktop I have a 'Internet shortcut' web link ... and again, they do nothing and also have the same 'generic' icon. When I right click for 'Properties', I only get 1 tab that says 'General' ... there is no 'Scortcut' tab in the Properties window.

    I tried to 'paste' one of the shortcut in this message ... but it won't. It was a link from Major Geeks on the 'Cleaning procedure for WinXP'.

    ----
    As to the BOOT.INI rebuild ... I need to read the link you provided. Since the 'Recovery Console' never installed after we ran [I believe] the ComboFix app a couple of times ... I'm guessing I'll need to turn to my XP install disk if there is no other way ... a tech friend has 'loaned' me his HIREN BOOT Utilities v10.5 disk that has a slew of apps on it ... might a solution be available from it ? just wondering.

    Once again ... Thank-you chaslange! Hope you're able to make sense of my descriptions and that we can get these final pieces put together ... then I'd like to inquire about making donations.

    Sincerely,
    RJHollins
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to remember what I said at the end of my 1st post to you ( message # 2 in this thread. Your use of ... which is not necessary is getting all of your messages trapped in the spam filters. You need to refrain from using these.

    I will give you one more fix ( in my next message ) for this and if it does not help, you will have to post in the Software Forum for this.

    Don't know whether Hiren's Boot CD has a utility to automatically rebuild the boot.ini file. You really should do this from the Recovery Console ( use your CD ) to make sure it is automatically built correctly. However you said your boot.ini file was blank. Your logs showed it to be 211 bytes in size.
    Code:
    "C:\"
    boot.ini May 31 2010 211 "boot.ini"
    So are you sure it is really blank?


    As an alternative to the Recovery Console, you could write the below to your c:\boot.ini file and save it. This is my best assumption at what your settings should be based on other logs:

    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try using ComboFix for your shortcut problem.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. RJHollins

    RJHollins Private E-2

    Hi chaslang,

    Lastest logs attached.

    Regarding IE Favorites. When I click on a favorite [bookmark] link, I now get a 'OPEN WITH' menu.
    First I tried linking it to Internet Explorer. It ask to 'OPEN' or 'SAVE'. Selecting open did nothing.

    Then I tried linking to 'Shell Doc Object and Control Library'. This DID open a new IE page to the bookmark link. So that does seem to be the one to use, but I need your confirmation on that.
    The same scenario holds true for IE links saved on the desktop.


    As to the BOOT.INI file. When I open to view it with Notepad, it shows no characters or numbers. Definately nothing as the text you recently posted.

    I do have another [old] computer with XP Pro installed. I emailed a copy of its' boot.ini file over to this computer [just in case]. The old computer boot file looks very similar to what you have posted.

    Old computer boot.ini looks like this:

    [boot loader]
    timeout=10
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
    C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons


    At this point, I'm not touching the boot file till I hear back from you after these log files, and observations on 'bookmark' favs. My concern is that the boot file may be 'locked' by Windows or something. I did read somewhere that the 'property' of this file has special settings. Again, I'll wait.

    Thank-you again!
    RJHollins
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below registry patch and then reboot and retest after rebooting.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    The c:\boot.ini file is a write protected hidden system file and the normal default size would be around 211 bytes like your log shows. Try the below.

    Click Start, Run, and enter cmd and click OK to open a command prompt. In the command prompt window, enter the below commands each followed by the enter key. Note there is a space after the cd, after the attrib, after each of the -r, -h and -s options and after the type.

    cd C:\
    attrib -r -h -s boot.ini
    type boot.ini


    Old computer boot.ini looks like this:
    The last line I highlighted above is there when the Recovery Console is installed. If you did not install the RC on the current PC we are fixing, then this line would not exist and this would basically be what I said you should have other than the time out which is not significant.
     
  18. RJHollins

    RJHollins Private E-2

    hi chaslang,

    ok, I ran the fixme.reg file as instructed.
    Message returned back that it was succesful adding to registry.

    After re-boot, still not working. This is both for bookmard favorites and web shortcuts saved to desktop. All related icons still have the generic look as a box with 3 small colored dots [red, blue, green].

    With the boot.ini I ran the CMD command and entered each command with a return in the dos box. No error message or anything. When I re-booted I still get the same INVALID Boot.ini message, and then Windows load up.

    I opened boot.ini within Notepad to have a look, still shows as a blank page.

    Still need your help please.

    Will wait to hear from you. THANK-You !

    Sincerely,
    RJHollins
     
  19. RJHollins

    RJHollins Private E-2

    Hello chaslang,

    I don't see a way to edit my previous post.

    Anyway, just noticed another IE issue that I wanted to bring to your attention.

    When I try to 'Send a Link' email, the webpage that I'm on will just close down. I use Outlook Express by default.

    Maybe this helps point to where the problem is ?

    thank-you
    RJHollins
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have one more thing for you to try. If it does not work, you will have to post in the Software Forum to continue on this since it does not appear to be due to malware but rather is a Windows setting that has been modified and I have given you all the standard fixes.

    • Print these instructions and then close your browser windows while performing these steps.
    • Click Start, Run and enter regedit and click OK. This should open the Windows Registry Editor
    • Navigate to:
      HKEY_CLASSES_ROOT\InternetShortcut
    • Backup this key by selecting it and then click File, Export. Save as .reg file.
    • Now delete InternetShortcut key by right clicking on it and selecting Delete
    • Now run Internet Explorer and select Tools, Internet Options, Programs
    • And select Reset Web Settings
    • Hopefully this will rebuild theURL association.
    • Reboot your PC to see if there is any change.
    Run the bootcfg command after booting to the Recovery Console from your CD as requested in message # 12
     
  21. RJHollins

    RJHollins Private E-2

    Hi chaslang,

    OK !! We have success with the IE shortcut/bookmark repair ! :)

    I've done only a preliminary check, but favorites & desktop shortcuts seem to be working.

    Wanted to get some 'happy' news back to you. Thanks for sticking with me on this.

    Alright, now to the Boot.ini stuff.

    I still have to get the RecoveryConsole installed [since it failed during Combofix runs]. I've printed the #12 message weblink you provided in regards to this.

    I may need a day or two to get to this, in order to prepare everything.

    Needless to say, me messin' with the BOOT file makes me somewhat nervous, as I have no back-up system on this computer.

    What would you recommend to provide some sort of 'safety net'. Is a 'System Restore Point' good enough ??? Would I be able to recover [even in SAFE MODE] should this not work as hoped ? The computer does boot to Windows now. [just a little hand wringing] :|

    If you ask, 'Why No Backup!", well the issue has been that every app I've tried to read up on seemed to have some kind of issues that others would bash. I do have a storage internal harddrive with a 500g partition that I could make available, and possibly use a floppy or CD to initiate a boot from should a catastrophe need be averted.

    Any insights or suggestions would be much appreciated. Especially before attempting the boot fix.

    Thank-you again!

    Sincerely,
    RJHollins
    [Up All Nite Studios]
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't you have your original Windows boot CD? If not, you could try what is in the below procedure to make a bootable recovery CD.

    http://tips.vlaurie.com/2006/05/recovery-console-for-those-without-an-xp-disk/

    System Restore is not a backup tool. It is a "system" restore where "system" is primarily necessary files and registry keys for the system (i.e., Windows).

    Backup important data onto CDs or DVDs or even large USB flashdrives. Or use the other 500 GB partition you mentioned.

    Poor excuse.;) Do you think no back at all is better idea than some minor issues of a backup program?
     
  23. RJHollins

    RJHollins Private E-2

    Hello chaslang,

    Yes I do have my original XP install disk.

    My specific question to 'system restore point' had to do with a safety net before repair of Boot.ini . I fully understand that this is no substitute for a complete back-up. Having been a recording engineer for the past 30 years, I fully appreciate the redundant back-up procedure.

    With my other computer, I use Acronis True Image for back-ups. HOWEVER, I have yet to ever perform a full restore from a back-up, nor any real need to access any of those files.

    This 'new' computer [the one under repair] is just now getting installed with all my necessary programs. This quad-core has 5 harddrives. The ONLY drive I would like 'backed-up' would be the main C:\ drive. This is a 300gig partition that is currently filled with 100gigs of OPSystem and certain data files. All other drives are storage related. All audio projects I manually back-up to gold Ti-Yudan DVD's. Our studio is looking at a possible 'RAID' solution for back-ups due to the sheer quantity of data. [All our work uses 32-bit float, and 44.1k, 88.2k or 96k sampling rates].

    For the moment, I wonder what is the best/most reliable backup app. Since I've not had to ever restore a computer, and having read user comments that this or that back-up failed, leaves me doubting or false sense of 'security'. I had hoped that MGeeks might have had a consensus or recommendation.

    If I just copied my C drive to another drive, would that be best? If my current C drive died, would I be able to use this back-up?

    I'd prefer to use an app that would do incremental back-ups, and should catastrophe happen, that I'd be able to force a boot to this back-up data.

    In your opinion, is 'Acronis True Image Home' a good choice?

    Thank-you for your insights.

    Sincerely,
    RJHollins
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but system restore cannot be run if Windows cannot be run. The only thing you could do would be to use your boot cd to copy registry hives as per this: http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech

    And also you could also just use the CD again to rebuild the boot.ini file again which would not change anything if it did not work the first time. If rebuilding your corrupted boot.ini file made the PC fail to boot at all in normal mode then it would be very unlikely that it would boot in safe mode.

    The place to inquiry about this is in the Software Forum. ;)

    No! It would not boot since you cannot copy all of the files from drive C to another drive. Some files are in use and even if you could manage to copy all the files to another drive, Windows would likely notice the hardware change and require a reactivation of the license.

    Again, better asked in the Software Forum but yes this is something many people use. I have no opinion on it whatsoever since I never used it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds