Please help me [RESOLVED]
Started by
ken65
, Jan 25 2008 11:03 PM
#31
Posted 29 January 2008 - 08:21 PM
#32
Posted 29 January 2008 - 08:35 PM
Ok let's see if it is still present.
Copy everything inside the quote box below (starting with dir) and paste it into notepad. Go up to "File > Save As" and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.
Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad here.
Copy everything inside the quote box below (starting with dir) and paste it into notepad. Go up to "File > Save As" and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.
dir C:\WINDOWS\dxdgns.dll /a h > files.txt
notepad files.txt
Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad here.
#33
Posted 29 January 2008 - 08:49 PM
Volume in drive C has no label.
Volume Serial Number is 20DF-1C31
Directory of C:\WINDOWS
06/13/2007 05:23 AM 34,636 dxdgns.dll
1 File(s) 34,636 bytes
Directory of C:\Documents and Settings\Ken\Desktop
Volume Serial Number is 20DF-1C31
Directory of C:\WINDOWS
06/13/2007 05:23 AM 34,636 dxdgns.dll
1 File(s) 34,636 bytes
Directory of C:\Documents and Settings\Ken\Desktop
#34
Posted 29 January 2008 - 08:55 PM
Please go to Start>Run type in Notepad.
Copy what is in the code box below into the open Notepad window.
Change the "Save As Type" to "All Files". Save it as delete.bat on your Desktop.
=====================
*Reboot your computer into SafeMode.
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.
Then please double click on delete.bat a window will open and close quickly.This is normal.
After that please reboot into normal windows and run the findfile.bat again and post the reults her in your next reply.
Copy what is in the code box below into the open Notepad window.
Change the "Save As Type" to "All Files". Save it as delete.bat on your Desktop.
@Echo off attrib -s -r -h "C:\WINDOWS\dxdgns.dll" del /q "C:\WINDOWS\dxdgns.dll" quitDon't do anything with this yet.
=====================
*Reboot your computer into SafeMode.
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.
Then please double click on delete.bat a window will open and close quickly.This is normal.
After that please reboot into normal windows and run the findfile.bat again and post the reults her in your next reply.
#35
Posted 29 January 2008 - 09:06 PM
Volume in drive C has no label.
Volume Serial Number is 20DF-1C31
Directory of C:\WINDOWS
Directory of C:\Documents and Settings\Ken\Desktop
Volume Serial Number is 20DF-1C31
Directory of C:\WINDOWS
Directory of C:\Documents and Settings\Ken\Desktop
#36
Posted 29 January 2008 - 09:15 PM
Time for some housekeeping
Also delete anything that we used that is left over.
===================================
After that Your log is clean.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
- Click START then RUN
- Now type Combo-fix /u in the runbox and click OK
The above procedure will:
- Delete the following:
- ComboFix and its associated files and folders.
- VundoFix backups, if present
- The C:\Deckard folder, if present
- The C:_OtMoveIt folder, if present
- Reset the clock settings.
- Hide file extensions, if required.
- Hide System/Hidden files, if required.
- Clean System Restore points.
Also delete anything that we used that is left over.
===================================
After that Your log is clean.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
#37
Posted 29 January 2008 - 09:21 PM
It says windows canot find Combo-fix /u make sure you type name correctly
#38
Posted 29 January 2008 - 09:31 PM
Sorry about that try it without the dash mark between combo and fix.
Like this Combofix /u
Like this Combofix /u
#39
Posted 29 January 2008 - 09:48 PM
Hi Thank you very much for the time and patients
Your help was greatly appriciated and my system is now clean. 1 last thing I would like to ask is when you say Clean System Restore points
can you please explain this to me thanks
Ken
Your help was greatly appriciated and my system is now clean. 1 last thing I would like to ask is when you say Clean System Restore points
can you please explain this to me thanks
Ken
#40
Posted 29 January 2008 - 10:05 PM
When you delete files they go to a place called system volume information.
If you were to do a system restore then you could re infect your self.
They are basically points that your computer uses to restore to.
You are welcome
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
If you were to do a system restore then you could re infect your self.
They are basically points that your computer uses to restore to.
You are welcome
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
#41
Posted 29 January 2008 - 10:15 PM
Can you please show me how to clean this restore point
#42
Posted 30 January 2008 - 02:56 AM
When you uninstalled Combofix it automatically cleans them.
#43
Posted 30 January 2008 - 05:53 AM
Again thank you for taking the time to help me with this issue
#44
Posted 30 January 2008 - 06:43 PM
You are welcome
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
#45
Posted 30 January 2008 - 06:43 PM
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users