Windows cannot login/access after avast deleted system.exe [ malware]

As topic stated , my windows , Windows XP SP3 Dark Edition V7 Rebirth couldnt log in nor access after avast suspecting and deleting system.exe[malware] in system32 folder. I cant even log into my windows using Any SAFE MODES or LAST KNOWN GOOD CONFIGURATION system. Both of them just stuck or hang . They just show the background and I couldnt use or open Task manager , as for safe mode , when it loading its files for safe modes , it stucked / hang. Please help encounter this problem. thanks.

Hello ,

20 minutes ago , a virus called system.exe attacked my computer , I had no choice but using avast to delete it , then it auto restarted me.. after it restarted..I cant even log to my windows XP a.k.a gaming windows ! Help ! T_T

p.s : im now on vista T_T

I tried to load my windows XP in safe mode , but it stucks + hangs , same as I load my XP in normal mode.. haiz..in that windows contains all important works.. I need to fix it a.s.ap..anyone can help me please ? After the window loaded and after I chose the USER , it loaded and show my desktop background , then suddenly it hang + stuck and stop loading , I had no choice but to press the Hibernate button a.k.a the start button to shut down.
Alex , I told ya , I event cant go into safe mode -.- it just hangs there ._. when loading up the files for safe mode -.-
What do you mean by that ? o_O
I have 3 partitions o_o

Those pictures are showing the system.exe has been deleted by my avast , but it auto restarts my computer and when I tries to login back to my XP , it just hangs like that T_T

http://i291.photobucket.com/albums/ll289/exp150/Untitled-1-1.jpg

http://i291.photobucket.com/albums/ll289/exp150/2-5-1.jpg

http://i291.photobucket.com/albums/ll289/exp150/1-4-2.jpg

bigger + clearer image :
http://i291.photobucket.com/albums/ll289/e…/Untitled-1.jpg
http://i291.photobucket.com/albums/ll289/exp150/2-5.jpg
http://i291.photobucket.com/albums/ll289/exp150/1-4.jpg

Summary : Cant login/access windows in ANY MODES : Safe mode , safe mode with network , safe mode with command promt , last known configuration blablabla after deleting teh malware/rookit/backdoor : SYSTEM.EXE using AVAST.

I’ve already tried to replace my explorer.exe + userinit.exe recommend by my friend , it still isnt working.

Hi exp150,

Best way turn off the system restore. Unplug the computer from the net from the back. Then place in safe mode and scan for a virus like normal. Then restart your computer. Turn your system restore back on. Then insert you OS cd - go to start - click on it - go to run. Click on run. Type sfc /scannow. Be sure after you type sfc you hit the space once. Then type the rest of the command.
It will repair any damage done to your OS. It will take a while so be patient,

polonus

Wow, polonus, you clearly didn’t read the original post. He can’t do that, because he can’t get that far!

Well, Exp150, you have basically 2 choices. Actually, 3.

  1. Put the hard drive from the affected (infected?) computer into another running Windows XP, determine the proper location of system.exe and copy the file back there. Put the hard drive back in and it should go. While you have it in the other machine, you might just scan it with Avast, just to be safe. If it finds any more infected system files, replace them as well.

  2. You can always use a Linux LiveCD to boot it into Linux, access the internet that way, download the file from one of the various file replacement places online, and hopefully that solves it. CAUTION: not all of those online file repositories are safe! Be sure you get the correct version of the file (at least one for Windows XP) and put it in the correct place. I like Puppy Linux because it has a small download, runs great, and gives a lot of fabulous tools.

  3. If you have a real Windows XP CD, you can do a repair install by booting from the CD, then selecting that installation for a repair (not the recovery console; go past that by indicating that you wish to install Windows, then select the partition with Windows on it, and press R, IIRC.)

Hope this helps. I do this stuff for a living, and know it’s not fun.

Hello,

Thank you for replying ! I dont have windows XP Original CD , I just download it from any warez websites to install my windows XP. Is it possible if I’m using the CD that I use to install the XP ?

Obviously I can’t encourage the use of Warez, but if you do, just be sure that you get one that is the same edition (home or professional) as the sticker so that you are at least quasi-legitimate.

If you’re able to download warez, you might as well download a copy of Puppy Linux and attempt to repair the Windows by replacing the missing file from online repositories. I suggest http://distro.ibiblio.org/pub/linux/distributions/puppylinux/puppy-4.1.2-k2.6.25.16-seamonkey.iso for a small download and a solid product. It’s easy to burn to a CD with Burnatonce http://www.burnatonce.net/files/bao0995.exe and includes an easy internet connection wizard “connect” on the desktop, and a basic but usable browser “browse” on the desktop.

Usually, just downloading the correct version of the missing file from an online file repository and saving it to the correct location is much faster than a repair install, where possible. Note that linux calls hard drives different things than Windows does…for example, if you’re using a Dell, your Windows folder is likely located on sda2, which Windows called drive C: but if it’s something else, it might be sda1 or sda3, all of which might be called C: in Windows. Just look around, it’s easy with Puppy. You’ll find it.

Hello ,
Thanks again for replying. I’ve tried using the non-original .iso bootable windows XP disk . After the formatting-like-system come out…it loading files…then suddenly it turns to BSOD. It asked me to do CHKDSK in command promt , which i’m doing now. In other forum , it suggest me to use malwarebytes and scan. This is my scan result.

http://i291.photobucket.com/albums/ll289/exp150/423-1.jpg

I’ll be doing the linux step soon.

I cant use the linux step , when i tried to burn it using burnatonce , it says ’ Error : Writable media blablabla ’

In other forum , it suggest me to use malwarebytes and scan.

Which other site are you seeking help on as advise may conflict…
If I read this right ,you say you have already used non-legit programs on there ( crack etc) ; they may well be the cause of your problems and you really do need to use only legitimate programs else your problems will increase

I can’t say what Burnatonce does under Vista, so you may need to find a utility which allows it to work under Vista.

However, if the same computer is working OK with Vista, you should be able to use Vista to repair XP. Just find the XP system.exe (you might have to use the install CD to find the file, as a quick online search doesn’t show it up at all) and put it back where it belongs.

One thing though…you sure that the system.exe file was legit? Perhaps you’re actually missing a different file, because I just looked for a system.exe on my working XP Pro box…it doesn’t seem to exist. Are you getting a BSOD with any information in it?

Thanks guys for replying and helping me. The problem was solved. Thanks again.