Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Nedd help with computer


  • Please log in to reply

#16
GodsElmo

GodsElmo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
I just downloaded them and will post a scan after lunch. Thanks. I am glad boot.ini took as well. plus having regedit back is real nice. GodsElmo
  • 0

Advertisements


#17
GodsElmo

GodsElmo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
blacklight found nothing. I am not sure we have the same version of it. mine says searching for hiden things and resulted in nothing. there was no log for it. Let me know if I ma doing this wrong.

11/10/05 13:19:18 [Info]: BlackLight Engine 1.0.25 initialized
11/10/05 13:19:18 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/10/05 13:19:19 [Note]: 4019 4
11/10/05 13:19:19 [Note]: 4005 0
11/10/05 13:19:54 [Note]: 4006 0
11/10/05 13:19:54 [Note]: 4011 1236
11/10/05 13:19:55 [Note]: FSRAW library version 1.7.1013
11/10/05 13:20:31 [Note]: 4007 0
  • 0

#18
GodsElmo

GodsElmo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
HKLM\SOFTWARE\Classes\webcal\URL Protocol 5/27/2005 8:23 PM 13 bytes Data mismatch between Windows API and raw hive data.
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\c89994489e374ee60488665751daad6f3b411190\metrics\data\CBA48D41-DAE3-4332-8F7B-4C8248F47EA.1131649553.tlv 11/10/2005 1:05 PM 7.75 KB Hidden from Windows API.


there was 2 things found with this other software. Let me know what ya want me to do next. Thanks GodsElmo
  • 0

#19
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Now lets see if we can get ya back in order.

Please make a backup of the entire registry before we begin-> Click Start-> Run-> Type in Regedit and click OK.

Make sure "My Computer" is highlighted and click File-> Export-> Save it to the Desktop as System.reg

This will place an backup of the entire registry on the desktop,should we need it later.


Im going to attach a Zip folder to the post-> Download and Unzip but dont run it just yet.


Download this Resolve tool from Sophos
http://www.sophos.co...rs/bagdlgui.com

Double Click bagdlgui.com to Open and Click Accept-> Click Configuration-> Place a tick by "Scan All Files" and "Verbose logging"-> Click Go to begin the scan.

The desktop will disappear and reappear and the scan will continue-> Once completed,the tool will create a log on the C drive.


After the tool has completed-> Be sure Windows is Showing Hidden Files
http://www.bleepingc...al62.html#winxp


Search for and Delete if found

C:\WINDOWS\system32\hloader_exe.exe

C:\WINDOWS\system32\hleader_dll.dll


Next,from the Zip folder you downloaded-> Double Click Clr.reg and allow it to merge into the registry.


Restart the PC-> Immediatly go to the Windows Update Site and attempt to acquire all the latest updates.

If there are any glitches,post back immediatly.

If no glitches,get your new AV and Firewall installed.


Once all is completed-> Post back with the Contents of the Sophos Resolve Tool log-> Located at C:\resolve.log

Attached Files

  • Attached File  Clr.zip   454bytes   32 downloads

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP