Vista virus
Jun 8 2009, 1:34 am
By: Forsaken Archer  

Jun 8 2009, 1:34 am Forsaken Archer Post #1



tl;dr: Main question: Is there anyway I can edit a registry from a non-booted windows vista on winxp?

So I have this computer I'm supposed to fix for someone. It has vista on it.
The computer is completely raped. It wouldn't boot up, so I tried system restore. I got to log in, but it takes like 20 minutes to load up and then 10 minutes for it to do anything, from opening a folder or loading a web page. I used msconfig to kill all 20+ startup objects and windows defender to kill processes that started up anyways (mysearchbar crap, horrible spyware - does not want to die!).
After like a year, I finally downloaded avast and did a scan at boot time and got rid of some trojans. Did help a little, but not completely. So I took the drive out and put it in my computer to scan it with kaspersky and currently doing a run with malwarebytes. So far the only thing that was detected was mysearchbar's main folder.
So besides the main question above, is there anything else I can do? It really seems like a lost cause but I can not just reformat it.



None.

Jun 8 2009, 1:38 am Heinermann Post #2

SDE, BWAPI owner, hacker.

Sure you can. Rape it some more. :)

A clean start will do that drive good, and save you some time. That someone is at a loss if he loses anything. It's his fault to begin with.




Jun 8 2009, 1:43 am ShadowFlare Post #3



Why do people always talk about reformatting when reinstalling Windows? Reformatting is rarely needed at all when reinstalling, even if it is to get rid of a virus, trojan, etc.

BTW, yes, there is a way with the registry editor to open a registry file from another copy of Windows. You just need the proper permissions to access the file. I don't know for certain whether XP's registry editor can safely work with Vista's registry or if it can't. If you have a Windows Vista installation disc, there is a way to open up the registry editor from there, IIRC. Something like getting into the command prompt from the recovery options in the Vista installer and then running regedit from there.

Whichever registry editor it is, the steps are the same. To open up the registry, first open up the registry editor. If you are opening up the user's registry, click on HKEY_USERS; if you want something from HKEY_LOCAL_MACHINE, highlight it. Then click File -> Load Hive. For HKEY_LOCAL_MACHINE, the different categories are stored at "C:\Windows\System32\config". The files with no extension are the current registry. For a user registry, the file is ntuser.dat in the user's root folder. (C:\Users\username on Vista)

After you select a file, it asks for a key name. Give it a name that isn't in the list yet (something simple like just an 'a' will work). This name is what will show up in the list after it loads it. You can then make changes in the registry loaded under that name. Be sure to click the loaded registry in the list and click File -> Unload Hive when you are done with it.

Post has been edited 2 time(s), last time on Jun 8 2009, 2:00 am by ShadowFlare.



None.

Jun 8 2009, 10:22 pm Forsaken Archer Post #4



Quote
Why do people always talk about reformatting when reinstalling Windows?
Because reinstalling only leaves a bunch of programs and application data laying around, no longer linked with windows.

I deleted a bunch of malware and useless crap on the computer. There must have been 25+ different shitty applications loading some data at startup. I almost had it running nicely, the only problem that persisted was random crashing of services, especially security ones, and it was running a tad slow, but no where as bad as it used to be. I got greedy and tried to uninstall the avast I put on there, to install kaspersky and malwarebytes, and apparently something took advantage of the small downtime where there was no antivirus. Desktop profile crashed and it would kill the ms installer service whatever when kaspersky was trying to setup.

Reformat is definitely going to happen now. I thought this would be an easy $50.



None.

Jun 8 2009, 11:36 pm ShadowFlare Post #5



You can just delete those files later when you decide you no longer need them. :P Windows Vista's installer makes it even easier, by keeping the old folders separate from the new ones, putting the old ones in Windows.old. Then it is a simple task to delete the old Program Files and Windows folders if you have no use for them.



None.

Jun 9 2009, 12:09 am Vi3t-X Post #6



Make a separate partition for his OS, and a separate for his random storage. Easy backup.



None.

Jun 9 2009, 4:03 am Vrael Post #7



Why couldn't you just reformat? Did you bet someone 50 bucks that you could fix it without reformatting or something?



None.

Jun 10 2009, 2:05 pm Forsaken Archer Post #8



Wasn't my computer, wasn't someone I knew. I wasn't told I could just reformat, so I assumed I should fix it without it.



None.

Jun 10 2009, 4:22 pm Falkoner Post #9



Malwarebytes, SUPERantispyware, Spybot - Search and Destroy, and maybe AdAware SE, scan with all of those, I'd say that if they stop detecting anything, might as well boot up off of it, prolonged scanning tends to get rid of the worst spyware, it'll take several "deletions" of the same spyware before you finally get it.



None.

Jun 10 2009, 5:07 pm Vi3t-X Post #10



Clean it in safe mode? :P



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[2026-4-18. : 3:57 am]
NudeRaider -- https://staredit.net/381600/ You have 5 minutes, then you can only edit your posts.
[2026-4-17. : 4:05 pm]
NudeRaider -- DarkenedFantasies
DarkenedFantasies shouted: you eat lots of beans
:lol:
[2026-4-17. : 11:30 am]
NudeRaider -- I would like 3000 minerals, please
[2026-4-16. : 7:32 pm]
Zoan -- I got $2000 bonus. I would like 2000 minerals, please
[2026-4-16. : 4:15 am]
DarkenedFantasies -- you eat lots of beans
[2026-4-16. : 3:46 am]
IskatuMesk -- how do i get gas
[2026-4-15. : 11:43 pm]
Moose -- you don't
[2026-4-15. : 10:06 pm]
Zoan -- how do i get minerals
[2026-4-14. : 11:45 pm]
ClansAreForGays -- Anyone wanna played Skewed StarCraft?
[2026-4-14. : 12:07 am]
Vrael -- NudeRaider
NudeRaider shouted: Vrael ranting still is though
you're a gentleman and a scholar, thank you
Please log in to shout.


Members Online: Zoan