D
djbeard83
Last weekend I started getting fake pop up ads telling me my computer was
infected and to download antivirus software. I did not click on any of them
and instead ran Malwarebytes' Anti-Malware off of a memory stick. It scanned
my computer and ID'd many infected files, went to repair them, then prompted
me to restart. After restarting the same problem existed, so I ran the
Anti-Malware again and a few minutes into the scan the screen went into a DOS
prompt saying that windows\system32\config\system was missing or corrupt.
Now this screen comes up every time I boot.
Today I tried following the steps here:
http://support.microsoft.com/kb/307545/. I successfully copied the default,
sam, security, software, and system files into a backup folder as it states,
then deleted the originals, then copied the files from the repair directory
(although I had to add .bak to my system file in the repair folder). This
worked fine except for the default and SAM files - here it asked me if I
wanted to overwrite the existing file (which I had already deleted), and when
I entered Y I received the message "File could not be copied." When I look
at the system32\config directory the security, software, and system files all
show a date of 3/26/06 (the dates that were in my repair directory, so these
were successfully copied over), but default shows 11/16/09 and SAM shows
11/17/09, which was the last day I successfully booted Windows. I have not
done anything further yet.
My questions are:
Why were SAM and default not deleted when I thought they were and why can't
they be overwritten?
Because these two files appear to have been altered while my computer was
infected, are they the cause of the problem?
What should I do next?
Is there still a chance of recoverying my data at some point?
Thanks for any help.
infected and to download antivirus software. I did not click on any of them
and instead ran Malwarebytes' Anti-Malware off of a memory stick. It scanned
my computer and ID'd many infected files, went to repair them, then prompted
me to restart. After restarting the same problem existed, so I ran the
Anti-Malware again and a few minutes into the scan the screen went into a DOS
prompt saying that windows\system32\config\system was missing or corrupt.
Now this screen comes up every time I boot.
Today I tried following the steps here:
http://support.microsoft.com/kb/307545/. I successfully copied the default,
sam, security, software, and system files into a backup folder as it states,
then deleted the originals, then copied the files from the repair directory
(although I had to add .bak to my system file in the repair folder). This
worked fine except for the default and SAM files - here it asked me if I
wanted to overwrite the existing file (which I had already deleted), and when
I entered Y I received the message "File could not be copied." When I look
at the system32\config directory the security, software, and system files all
show a date of 3/26/06 (the dates that were in my repair directory, so these
were successfully copied over), but default shows 11/16/09 and SAM shows
11/17/09, which was the last day I successfully booted Windows. I have not
done anything further yet.
My questions are:
Why were SAM and default not deleted when I thought they were and why can't
they be overwritten?
Because these two files appear to have been altered while my computer was
infected, are they the cause of the problem?
What should I do next?
Is there still a chance of recoverying my data at some point?
Thanks for any help.