Restoring registry on a removed disk

I appologise if this has been entered before but I was not sure what to search for.

I recently tried to remove a Trojan from my system and deleted some registry entries by mistake. Before I realised I ran CCleaner and tidied everthing up. The laptop will not now load any accounts. Windows loads and the desktop background photo appears but there are no icons or task bar, after a while it shuts down.

I removed the HDD and copied over important stuff to my PC.

I have been using CCleaner for a while so I have a few backups. Is there any way I can leave the laptop HDD connected to my PC via USB and use one of these backups to restore the registry on the laptop HDD?

For ever hopeful

Sid

I believe CC reg restore only works if your actually in the Windows OS you removed it from.

You could try to boot from that drive (again) by hitting F8 key about once per second after hitting power on button (to bring up safe mode option).

Once in the admin safe mode account, try importing the entries & see if you can reboot into Windows.

If the taskbar still does not load, try hitting CTRL + ALT + DEL to bring task manager up.

Click File on the menu at the top, then click New Task (Run...)

Type explorer.exe & hit enter. Sometimes this can bring it back up.

Hi Sid, and welcome to Piriform.

I recently tried to remove a Trojan from my system and deleted some registry entries by mistake. Before I realised I ran CCleaner and tidied everthing up.

Sounds like you ran CCleaner after you accidentally deleted the registry entries. CCleaner only backs up the entries it deletes and not the entire registry.

Even earlier back-ups won't contain the missing registry items the removal of which has screwed up your laptop.

Which operating systems are we talking about here Sid, as it is possible to replace corrupt registry hives from backups Windows created when the Operating System was installed. Although these will be way out of date, they'll at least, with any luck, enable you to boot up successfully.

Alternatively, if System Restore was running on the laptop, it's possible to retrieve more up to date copies of the registry hives from within the "System Volume Information" folder (System Restore)?

An example of the two process here for XP ...

http://support.microsoft.com/kb/307545

But maybe, considering the initial cause of your problems, it would be wise to seek help from a malware removal expert, as any malware remaining on your laptop could probably screw up any repair you make.

Have a look here ...

http://forum.pirifor...ndpost&p=208046

I'm a huge fan of backups. Backups are as important to computing as petrol is to a motorcar. If you have recent backups I'd restore and rebuild from there. 1st thing to do is ensure the integrity of your user(s) data. Pictures, music, documents, and so forth. Secure that first.

Dennis' advice is different than mine, but also sound. What is the backup program you used? Does it facilitate restoration of a single file that you can select by browsing the image? If so, you can pull the registry from there. It might not be totally up-to-date, but would give you access like before.

But, you cannot use backups created by ccleaner. They are incomplete and only capture the changes effected by ccleaner itself. An undo function to fix any errors ccleaner may have made. Any entries you deleted are likely gone by now.

My take on malware trojans, well -(it's harsh and not everybody likes it) - is to nuke it from orbit, it's the only way to be sure. I quit fighting those damned things a long time ago.

But for now, we need to know what you've got backed up.

It may be worth considering the possibility that your Laptop HDD is not entirely free of trojan infestation,

and by connecting it to your P.C. you may have allowed the trojan to infect the P.C. whilst it was connected,

and even plant a key-logger ready for credit card and bank account transactions even with the Laptop HDD now disconnected.

sixpsid I strongly recommend you read here and follow its advice.

http://forum.piriform.com/index.php?showtopic=34786&pid=208046&st=0&&do=findComment&comment=208046

ATTN HAZEL

I clicked on the link and it took me to

Speccy on Bulgarian language

I suspect you intended something like

http://forum.pirifor...hp?showforum=12

or

http://forum.piriform.com/index.php?showtopic=34786

Thanks Alan, you guessed right and I have edited my original link.

Thank you for everyone's comments and advise.

I have tried your suggetsions Super Fast but I believe the laptop is going to need a reload of XP Pro. It was getting a bit dodgy anyhow as I have not been able to boot into safe mode for a while.

I know that it was a high risk strategy to connect the HDD to my PC but I needed to get all of the Mrs's photos off first (definitely worth the risk). I turned on a few malware progs and just accessed the disc the minimum amount. Luckily nothing transfered.

Thank you

Sid