6/17/08

Edit registry offline

A Windows XP box came into our shop, infected with malware last Friday.  It would boot part way into Windows and then crash with a BSOD stating something like "Unable to load basebow32.dll – unable to load the application, reinstalling might fix this".  To fix, I placed the infected HD in a clean Windows XP box (as a secondary drive), launched regedit, clicked on HKEY_Local_Machine, went to the File menu, Load Hive, and selected the Infected_Drive\Windows\System32\config\SYSTEM file.  Searched it for references to "basebow32" and removed them.  Problem solved!