Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Pending] HJT Logs
Register for a Free Account

[Pending] HJT Logs - restore hp pc posted in the Security & Safety forums; chiaz there is a check on word wrap, the logs keep coming up like that. Should i start over....


Reply
Scan your PC for Errors
Old 04-02-2009   #8
Bronze Member
 
Join Date: Apr 2009
Posts: 54
PC Experience: Some Experience
Default Re: restore hp pc

chiaz there is a check on word wrap, the logs keep coming up like that. Should i start over.
bmorrisey is offline   Reply With Quote
Advertisement - Register to Remove
Old 04-02-2009   #9
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: restore hp pc

OK let's not get stuck at the small details.

Next let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:

Go here ======> A guide and tutorial on using ComboFix <====== Go here

Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should get a prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
(2) Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review (copy and paste them, not attach), so that we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log

Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.
chiaz is offline   Reply With Quote
Old 04-02-2009   #10
Bronze Member
 
Join Date: Apr 2009
Posts: 54
PC Experience: Some Experience
Default Re: restore hp pc

ComboFix 09-04-01.01 - Owner 2009-04-02 8:34:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.139 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\.exe
c:\windows\system32\bszip.dll
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\irdvxc.exe
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://sunmicro.ht.rd.llnw.net
c:\windows\system32\lsass.exe . . . is infected!!
c:\windows\system32\services.exe . . . is infected!!
c:\windows\system32\svchost.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSDISK
-------\Service_MSDisk

((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
2009-04-01 19:33 . 2009-04-01 19:33 <DIR> d-------- C:\New Folder
2009-04-01 16:40 . 2009-04-01 16:40 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-04-01 16:39 . 2009-04-01 16:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-01 16:39 . 2009-04-01 16:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-01 16:39 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-01 16:39 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-30 07:12 . 2009-03-30 13:53 342,048 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-03-30 07:12 . 2009-03-30 17:00 90,656 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-03-30 07:12 . 2009-03-30 07:12 32 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-03-30 07:12 . 2009-03-30 07:12 32 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-03-28 21:42 . 2009-03-31 05:14 <DIR> d-------- c:\documents and settings\Owner\Application Data\DMCache
2009-03-28 21:28 . 2009-03-28 21:28 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-28 16:24 . 2009-03-28 16:25 <DIR> d--h----- c:\windows\msdownld.tmp
2009-03-28 11:49 . 2009-03-28 11:49 <DIR> d-------- c:\program files\RegCure
2009-03-15 07:07 . 2009-03-15 07:07 <DIR> d-------- c:\program files\alot
2009-03-15 07:07 . 2009-03-31 17:17 <DIR> d-------- c:\documents and settings\Owner\Application Data\alot
2009-03-09 14:55 . 2009-03-09 14:55 <DIR> d-------- c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-04-02 14:42 3,836 ----a-w c:\windows\viassary-hp.reg
2009-04-02 14:42 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-02 11:41 --------- d-----w c:\program files\LimeWire
2009-04-02 11:38 --------- d-----w c:\documents and settings\Owner\Application Data\LimeWire
2009-04-02 00:00 --------- d-----w c:\program files\Norton Security Scan
2009-04-01 22:03 --------- d-----w c:\program files\iTunes
2009-04-01 22:03 --------- d-----w c:\program files\iPod
2009-04-01 11:18 --------- d-----w c:\program files\DefenderPro
2009-03-31 20:02 --------- d-----w c:\program files\Google
2009-03-30 23:32 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-30 23:31 --------- d-----w c:\documents and settings\All Users\Application Data\Defender Pro
2009-03-28 17:58 --------- d-----w c:\program files\Java
2009-03-28 12:29 --------- d-----w c:\program files\Norton AntiVirus
2009-03-25 14:01 --------- d-----w c:\program files\Defender Pro
2009-03-19 22:15 --------- d-----w c:\documents and settings\Owner\Application Data\AdobeUM
2009-03-18 21:47 --------- d-----w c:\program files\Easy Internet signup
2003-08-29 03:16 32 --sha-w c:\windows\{14B431FF-99E9-4C1E-8574-051F227CB5BD}.dat
2004-08-04 06:56 164,746 --sha-r c:\windows\system32\xlnia.dll
2003-08-29 03:16 32 --sha-w c:\windows\system32\{C6B785D4-A2EC-4320-AADD-7778E174E81D}.dat
.
------- Sigcheck -------
2002-08-29 06:00 19968 9f0f424bb86399b7ebf0a4f8de995971 c:\windows\$NtServicePackUninstall$\svchost.exe
2004-08-04 00:56 21504 fcd11649990452c980ba484d419f1d0b c:\windows\ServicePackFiles\i386\svchost.exe
2008-04-13 18:12 21504 8d1d5cc770ac5cb902157b0da960f53d c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\svchost.exe
2004-08-04 00:56 21504 4183f6f0bc26bca965d69acdd78faf91 c:\windows\system32\svchost.exe
2004-08-04 00:56 1039360 852067be424964435b3941d3d207f98c c:\windows\explorer.exe
2002-08-29 06:00 1011200 7b9524db853dabdb4d1f7a35cf052b4a c:\windows\$NtServicePackUninstall$\explorer.exe
2004-08-04 00:56 1039360 33d337a321dddd16890dbe1ae432ccfd c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-13 18:12 1040896 603c0b1963f1e772dfaa79db5e5514d4 c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\explorer.exe
2002-08-29 06:00 108544 cfd63f340a8bcfce1a262099c6f8d1ea c:\windows\$NtServicePackUninstall$\services.exe
2004-08-04 00:56 115200 985af5b81798a7b5e0a2744178929e50 c:\windows\ServicePackFiles\i386\services.exe
2008-04-13 18:12 115712 61a0b116be06417948656475feab2178 c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\services.exe
2004-08-04 00:56 115200 e4873033e7ce2766f8c7feb440779411 c:\windows\system32\services.exe
2002-08-29 06:00 18944 2a8f517634ee220827ef916debf9161c c:\windows\$NtServicePackUninstall$\lsass.exe
2004-08-04 00:56 20480 46ef5da4090259cc4eb0e66787cb3ac6 c:\windows\ServicePackFiles\i386\lsass.exe
2008-04-13 18:12 20480 5f4b463fbc3a68b400066d4751a3995e c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\lsass.exe
2004-08-04 00:56 20480 4200777422d104517ccfc5fb475c467c c:\windows\system32\lsass.exe
2002-08-29 06:00 20480 3250464487bb0e29467d223d2861d691 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 00:56 22528 e7823e952793139432825a42c0e94b1b c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-13 18:12 22528 c0f902097f3c674839d820f1c2ecd878 c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\ctfmon.exe
2004-08-04 00:56 22528 e35aa8079683c53876761197b43c8ae9 c:\windows\system32\ctfmon.exe
2002-08-29 06:00 58368 6ff5476ad381d1e2e14a614f487a1b59 c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 00:56 65024 c5a9946dd08c140c7582fba601b52641 c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-13 18:12 65024 63bb017eaca8454035628bdcf1b4f2f9 c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\spoolsv.exe
2004-08-04 00:56 65024 ef8e038f4813e4983e6164e9a00b9337 c:\windows\system32\spoolsv.exe
2002-08-29 06:00 146944 2acf005cc1d4f1f3f13cf708a086801f c:\windows\$NtServicePackUninstall$\wuauclt.exe
2004-08-04 00:56 118272 b7809b29572c73b24fab9dcb3c3c9162 c:\windows\ServicePackFiles\i386\wuauclt.exe
2008-04-13 18:12 118272 417ee48e745fb277ce3d347253d528c3 c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\wuauclt.exe
2004-08-04 00:56 118272 38b0ccab300128a08e4cbd615de1028c c:\windows\system32\wuauclt.exe
2002-08-29 06:00 29184 d5312b133560aa2cff2f6360a1384544 c:\windows\$NtServicePackUninstall$\userinit.exe
2004-08-04 00:56 31744 13058a63f29ba8cb5c8a295b8fbd4209 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-13 18:12 33280 13a0ea68a71c51931a89cd7d1c3d39bf c:\windows\SoftwareDistribution\Download\59fc8f12b 80caa991163249076d0bcca\userinit.exe
2004-08-04 00:56 31744 5ab6099859b3b5a02bdc9f518cba3b2f c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 32768]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1674752]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2002-07-17 208959]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 22528]
"NVIEW"="nview.dll" [2003-05-03 c:\windows\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 59904]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 122880]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 57344]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 57344]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 491520]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 69632]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 163840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 159789]
"AutoTKit"="c:\hp\bin\AUTOTKIT.EXE" [2003-06-18 66092]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 221184]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 90112]
"NAV CfgWiz"="c:\progra~1\NORTON~1\Cfgwiz.exe" [2002-11-15 476792]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-11-15 54976]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-11-15 59072]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-08-09 147456]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-06-17 126976]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-02-24 61440]
"KEMailKb"="c:\progra~1\MICROI~1\INTERN~1\KEMailKb .EXE" [2005-08-09 409600]
"KPDrv4XP"="c:\progra~1\MICROI~1\INTERN~1\KPDrv4XP .EXE" [2005-02-21 49152]
"LaunchAntiSpy"="c:\program files\DefenderPro\TSAntiSpy.exe" [2007-03-07 1564672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 421888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-28 148888]
"nwiz"="nwiz.exe" [2003-05-03 c:\windows\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 c:\windows\ALCXMNTR.EXE]
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-18 66092]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-07 34304]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Adobe Media Player.lnk - c:\program files\Adobe Media Player\Adobe Media Player.exe [2008-11-02 267264]
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2003-08-23 36864]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSubtract.exe [2003-08-28 561152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-06-13 241664]
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2002-09-20 61440]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-08-23 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 04:50 40960 c:\program files\Softex\OmniPass\OPXPGina.dll
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"6178:TCP"= 6178:TCPfjktb
R2 HIDKbFlt;HIDKbFlt.SvcDesc%;c:\windows\system32\dri vers\HIDKbFlt.sys [2005-07-25 23680]
S2 mrtRate;mrtRate; [x]
S2 zzykti;System Support;c:\windows\system32\svchost.exe -k netsvcs [2003-08-08 21504]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
zzykti
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-17 c:\windows\Tasks\AntiSpy.job
- c:\program files\DefenderPro\TSAntiSpy.exe [2007-03-07 06:41]
2009-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-18 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2003-05-23 17:13]
2009-04-02 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2009-03-11 20:20]
2009-04-02 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]
2009-04-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]
2009-03-31 c:\windows\Tasks\WebReg officejet 4300 series.job
- c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2002-12-11 00:09]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe

.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
uDefault_Search_URL = hxxp://srch-us9.hpwis.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://srch-us9.hpwis.com/
uInternet Connection Wizard,ShellNext = hxxp://us9.hpwis.com/
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: SpSubLSP.dll
TCP: {848426D5-804E-4366-AAC3-C23C5DC578CA} = 216.49.224.10 216.49.224.11
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
************************************************** ************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-02 08:43:14
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\z zykti]
"ServiceDll"="c:\windows\system32\xlnia.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\program files\Bonjour\mdnsNSP.dll
c:\windows\system32\klogon.dll
c:\program files\Softex\OmniPass\opxpgina.dll
- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\SpSubLSP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton AntiVirus\Navapsvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Softex\OmniPass\omniServ.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\rundll32.exe
.
************************************************** ************************
.
Completion time: 2009-04-02 8:49:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-02 14:49:21
Pre-Run: 90,993,217,536 bytes free
Post-Run: 93,098,643,456 bytes free
248
bmorrisey is offline   Reply With Quote
Old 04-02-2009   #11
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: restore hp pc

Thanks for posting the log. I'm sorry but I have to turn in now. Will get back to you as soon as possible.

Thanks for understanding.
chiaz is offline   Reply With Quote
Old 04-03-2009   #12
Bronze Member
 
Join Date: Apr 2009
Posts: 54
PC Experience: Some Experience
Default Re: restore hp pc

chiaz iknow the need for sleep, but i am in need for this computer. i was wondering if anyone else could read this log and help me out. i appreciate all of your help. thank you bmorrisey
bmorrisey is offline   Reply With Quote
Old 04-03-2009   #13
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: restore hp pc

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:



Files::
c:\windows\viassary-hp.reg
c:\windows\system32\xlnia.dll

Folders::
c:\program files\alot
c:\documents and settings\Owner\Application Data\alot

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\E]

Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.


Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt in your reply.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall. Altering this script in any way could damage your computer.*


Do you have your Windows CD?
chiaz is offline   Reply With Quote
Old 04-03-2009   #14
Bronze Member
 
Join Date: Apr 2009
Posts: 54
PC Experience: Some Experience
Default Re: restore hp pc

chiaz idon,thave a windows cd
bmorrisey is offline   Reply With Quote

Reply


Bookmarks

Tags
hp, pc, Pending:, restore
Similar discussions...
Thread Thread Starter Forum Replies Last Post
PC restore clwlls8 General Software 1 04-19-2009 12:32 AM
Restore tcassel Windows XP/2000 8 11-26-2008 09:39 PM
What does Syst. Restore actually restore?? CrazyKate Windows XP/2000 12 01-09-2007 03:19 PM
How to restore a PC? hibs1875 Unfinished Threads 1 08-25-2006 11:19 AM
Information: HP Restore merlin General Application Tutorials 0 10-17-2005 02:23 AM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 01:20 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2