brandonrobison.net
「自由か死!」

A mystery in the making

October 13th, 2008 by Brandon

To my computerly-nerdy friends, especially the ones more computerly-nerdy than me. Please help me figure this out!

I got hit with some malware tonight. Malware, for those of you not in the know, is short for malicious software, eg. viruses, spyware, etc. I won’t go into how I got infected with said malware, but rest assured it was not porn-related. Anyway.

My computer almost grinded to a halt. I tried force-quitting several applications that didn’t look familiar, but to no avail. I figured I would restart and try it again once Windows rebooted. Well, that didn’t work: Windows wouldn’t reboot. It would get about halfway there and just pause indefinitely. And thus the inevitable began: a reinstallation of the Windows Vista Operation System.

Luckily, I had enough foresight to set up my file system in such a way that I would only lose about 1% of my data in the event of such a crash. All of my personal data (documents, pictures, music, etc.) are stored on a separate drive. Specifically, all of my stuff is located in D:\Users\Brandon. The default for Vista is C:\Users\Brandon. I know… not very original.

So I got Vista all reinstalled and I went into the Users folder, right-clicked on the different folders, and told it to “move” the location. I then went into the registry editor to find any other spots that this “automatic” method hadn’t affected. Once I was finished, I restarted.

When Vista rebooted and asked me to enter my password, I did so. It said “Loading” … and then a few seconds later, “Logging Off”. It wouldn’t boot into Windows. Unless I did it in Safe Mode.

I thought maybe something weird had happened by my doing the move location method mentioned two paragraphs previously. So in Safe Mode, I looked at the registry. I found dozens of new keys pointing to D:\Users… which had not been there before. Well, I mean, they had been there before I had reinstalled Windows. But now they were back again. Where had they come from? This only made me suspect the move location method even more. So I decided to format and reinstall — again.

This time I did everything manually in the registry editor. Before I started changing the Users folder location, I checked to see if there was anything pointing to D:\Users. There were no keys. I changed the couple dozen C:\Users… keys, restarted, and BOOM. Same freaking problem. Again, checking regedit in Safe Mode revealed a bunch of “old” keys.

HOW ARE THESE THINGS RESURRECTING???

The third installation is now about to finish, but it’s also almost 1:30am and I have to wake up early for work tomorrow. I’m going to play with this a little bit more and then go to sleep. But if anyone has any ideas, please let me know.

UPDATE: Victory! I got it to work… and I will explain how later, in the comments. Now, I’m going to bed.

One Response

  1. Brandon

    Basically, when I was pointing Windows to my old data locations, it was picking up remnant hidden data — the same stuff which had messed up my computer in the first place. Rather than point Windows to the same place, I moved all my data to a temporary location, referred it to the location, and then moved the files back which were pertinent, eg. music, pictures, documents.

    Either way, it’s been a huge pain.

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.