help with sys restore: problems after running GMER
#21
Posted 16 February 2010 - 03:25 PM
It sounds like you ended up into Vista's recovery environment. Are you able to access c: drive there (by typing command c: in command prompt)?
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#22
Posted 16 February 2010 - 03:49 PM
Hi,
It sounds like you ended up into Vista's recovery environment. Are you able to access c: drive there (by typing command c: in command prompt)?
I believe I can
It comes up with C:\>
#23
Posted 16 February 2010 - 05:28 PM
cd\windows\erdnt
dir
You should see directories with timestamps. Look for one that matches your backup moment.
Then give these commands in c:\windows\erdnt location (replace nameofthefolder with correct folder name):
cd nameofthefolder
batch erdnt.con
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#24
Posted 17 February 2010 - 04:05 AM
Good. Try following commands in c: drive:
cd\windows\erdnt
dir
You should see directories with timestamps. Look for one that matches your backup moment.
Then give these commands in c:\windows\erdnt location (replace nameofthefolder with correct folder name):
cd nameofthefolder
batch erdnt.con
for the first command cd\windows\erdnt dir
it says the system cannot find the path specified
This is how it looks when I type it in, not sure if it was right.
C:\>cd\windows\erdnt dir
i also tried
C:\>cd\windows\erdnt
When i put ERDNT on my computer I didn't use the installer, i Just extracted the files into a folder on my desktop. I can't remember what I named the folder, but If I could somehow browse through them I would know which one it was. That is also where the .exe file for ERDNT was saved, incase I needed to back it up.
#25
Posted 17 February 2010 - 04:57 PM
Please run this command in command prompt:
dir /s/a \erdnt.con
Note down locations (if any).
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#26
Posted 17 February 2010 - 05:26 PM
Hi,
Please run this command in command prompt:
dir /s/a \erdnt.con
Note down locations (if any).
It says
Volume in drive C is S3A6274D004
Volume Serial Number is FE5D-6C8E
Directory of C:\Users\Roo\Desktop\reg backup\7-02-2010
#27
Posted 17 February 2010 - 05:32 PM
In command prompt, type these commands one by one (hit enter after each):
c:
cd\Users\Roo\Desktop\reg backup\7-02-2010
batch erdnt.con
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#28
Posted 17 February 2010 - 05:45 PM
Hi,
In command prompt, type these commands one by one (hit enter after each):
c:
cd\Users\Roo\Desktop\reg backup\7-02-2010
batch erdnt.con
it says
'batch' is not recognized as an internal or external command, operable program or batch file.
#29
Posted 17 February 2010 - 05:51 PM
While still in C:\Users\Roo\Desktop\reg backup\7-02-2010 folder please type this:
erdnt.exe
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#30
Posted 17 February 2010 - 05:57 PM
Hi,
While still in C:\Users\Roo\Desktop\reg backup\7-02-2010 folder please type this:
erdnt.exe
it comes up with a pop up saying
with this program you can restore a registry backup of your windows NT/2000/XP system.
i have vista though, should I click on okay?
#31
Posted 17 February 2010 - 06:04 PM
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#32
Posted 17 February 2010 - 06:09 PM
Yes, allow it to restore.
okay, done it. Computer still seems the same though. Should I restart my computer?
Is there anything else I should do while I still have this vista recovery window open, I had trouble getting into it last time trying to get the right timing when pressing esc.
#33
Posted 17 February 2010 - 06:11 PM
After ERUNT has done its job please reboot and see if you're now able to log into normal mode properly.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#34
Posted 17 February 2010 - 06:20 PM
Hi,
After ERUNT has done its job please reboot and see if you're now able to log into normal mode properly.
nope doesn't work. still the same.
#35
Posted 17 February 2010 - 07:31 PM
Then I'm afraid the only solution is to backup your important documents, music, pictures and videos to removable drive in command prompt and then use that Toshiba recovery wizard (available in that advanced bootup menu) to restore system back to factory defaults.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#36
Posted 18 February 2010 - 12:38 AM
Hi,
Then I'm afraid the only solution is to backup your important documents, music, pictures and videos to removable drive in command prompt and then use that Toshiba recovery wizard (available in that advanced bootup menu) to restore system back to factory defaults.
how do I back up things from command prompt? I do not need all of the c drive backed up, I have most things. I just need a few folders and files, but I can't remember exactly what they're called or where they are. Is there some sort of way of just browsing the files and then choosing which ones I want?
Also do u think I should try system restore first? Or do you think that the malware might block it from running completely?
Edited by ArthurOPlasty, 18 February 2010 - 08:32 AM.
#37
Posted 18 February 2010 - 03:32 PM
You can use dir command for searching. If you recall file/folder names we can try to create a batch that lists the locations.how do I back up things from command prompt? I do not need all of the c drive backed up, I have most things. I just need a few folders and files, but I can't remember exactly what they're called or where they are. Is there some sort of way of just browsing the files and then choosing which ones I want?
Yes, you could attempt that since the option is available there.Also do u think I should try system restore first? Or do you think that the malware might block it from running completely?
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#38
Posted 18 February 2010 - 04:38 PM
Hi,
You can use dir command for searching. If you recall file/folder names we can try to create a batch that lists the locations.
Yes, you could attempt that since the option is available there.
sys restore worked, I can see my desktop now. Still got the malware though, I could not restore to a point before the infection, there was not anything listed.
i'm running adaware now to quarantine the file, then will run hijack this and post the logs.
Should I try running GMER again?
#39
Posted 18 February 2010 - 04:47 PM
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
- When done, DDS will open two (2) logs:
- DDS.txt
- Attach.txt
- Save both reports to your desktop. Post them back to your topic.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#40
Posted 19 February 2010 - 05:04 AM
Attached Files
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users


This topic is locked









