Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

help, virus has just overwritten registry hive (software)

Status
Not open for further replies.

commun1

Programmer
May 26, 2004
41
DE
I just had a stupid virus without me noticing it (scan couldn't delete it), I wanted to boot in safe mode but bang, I couldn't log on after reboot. I went to the recovery console and looked into /system32/config where the complete software hive named "software" has been overwritten by that virus!

I took the one from the /repair/-Folder so I could boot the system again. I could log on but all my personalized data is gone or not accessible like profile settings, outlook 2003 does not load, most programs say they're not loadable though they are all there, Windows Installer doesn't work eitherways.

I logged on with my regular user however it doesn't show up with its desktop but shows a clean one instead, like I would just have installed a new OS... looking into the profiles folder shows me that the original users are still there but a new user has been created named olduser.newuserwithsamename...

Question is, is there a way for getting back my original software registry hive that was located at /system32/config ?

I have no backups of the registry at all and no restoring points made ... stupid me ...

virus is gone but old registry too... please help =(

Btw I have found a software hive which is like 22 MB big and looks like its a current one but when I load it in regedit it only shows a few entries and not the original registry structure with all its subfolders in it, maybe it's the overwritten one??
 
thank you for this link...

in my research I found out that there was a copy of my registry within the repair-folder, the file was just renamed to sys3 but was the most recent one...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top