Using ERD Commander
Go to Start ->Search.
Search for the following strings independently:
DLLCACHE
HAL.DLL
If found, let me know their location.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Hi, BillPro
Since the Recovery Console is booting to the Root directory and not to the Windows Folder, then I have to agree with steamwiz, that something happened after running Combofix. Please follow any of the Options below and let me know any problems you may encounter, and outcome:
First option:
Slave the drive in another compurer and follow the instructions similar to the instructions below to move the System32.vir folder to the Windows folder, then rename both, the System32.vir to System32 and the Qoobox folder to QooBox-OLD in this drive.
Second option:
Use ERD Commander:We need a special tool from Microsoft. It's a hefty 64.3 MB download but it's worth the trouble.
Please download & install the Microsoft Diagnostics and Recovery Toolset
Once you have it installed, locate the file :
C:\Program Files\Microsoft Diagnostics and Recovery Toolset\erd50.iso
It's an ISO file which you may burn onto a CD.
Reboot the machine with the ISO CD
You will receive the above message. Ignore it & continue
From Desktop, double click on 'My Computer'
Navigate to C:\Qoobox\Quarantine\C\Windows
Right click on the System32.vir folder & select "Move To ..."
Move it to the C:\Windows folder
Then Navigate to the C:\Windows & rename the folder from System32.vir to System32
The C:\QooBox folder should also be renamed to C:\QooBox-OLD
Restart the machine & remove the CD.
With any luck, your machine shall be accessible again
In case you deleted some folders in the process, ERD Commander has a feature called 'File Restore'. See if that can find the files or folders deleted.
Keep us posted.
Neither file was found using the File Restore feature of the ERD. The search included deleted directories.Sorry for the delay. Needed to know if ERD Commander has a search tool.
Using ERD Commander
Go to Start ->Search.
Search for the following strings independently:
DLLCACHE
HAL.DLL
If found, let me know their location.
Well then, to answer your question...Yes I could use some guidance on a fresh install. I do have an external hard drive that I've used Bounce Back to keep a second copy of my data. Obviously I'm concerned that the drive is harboring one or more of whatever brought down my internal drive.Hi, BillPro
That spells bad news. The entire System has been wiped-out of the computer. The only option would be to use the Recovery CD to perform a destructive restore of the computer to factory settings, or if the computer is not part of a brand name, it must be reformatted and the operating System re-installed.
I am very sorry. We still cannot say it was Combofix, as if that would had been the case, the operating system would had been recovered. Chances are there was a backdoor trojan that wiped the system once detected being removed. It is not the first case.
Do you need assistance with the use of the Recovery CD or Windows' installation?
You have better chances winning the lottery. Don't worry about that.I do have an external hard drive that I've used Bounce Back to keep a second copy of my data. Obviously I'm concerned that the drive is harboring one or more of whatever brought down my internal drive.
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.