Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93084 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Resolved] Clock keeps reseting to 12 April 2016!


  • This topic is locked This topic is locked
141 replies to this topic

#46 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 06:44 AM

Try
cd /windows/ERDNT
Then type
dir
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

    Advertisements

Register to Remove


#47 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 06:50 AM

I am on (D:\WINDOWS\system32\config) and typed cd/windows/ERDNT but it could not find the specified path

#48 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 06:52 AM

Navigate through the explorer to My Computer, D:, Windows and see if there is an ERDNT folder there. Are you sure this is your normal c:?
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

#49 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 06:57 AM

my mistake - I re typed from D: D:\WINDOWS\ERDNT>dir volume in drive D has no label. Volume Serial Number is 1403-B6F1 Directory of D:\WINDOWS\ERDNT 11/07/2009 02:02 PM <DIR> . 11/07/2009 02:02 PM <DIR> .. 11/07/2009 02:10 PM 240 CFUNDO.dat 11/07/2009 02:04 PM <DIR> Hiv-backup 1 File(s) 240 bytes 3 Dir(s) 12302602240 bytes free

#50 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 07:00 AM

From where you are now (D:\Windows\ERDNT)

cd hiv-backup

copy system d:/windows/system32/config/system

Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

#51 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 07:02 AM

it says that the syntax of the command is incorrect

#52 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 07:04 AM

(although I am on d:\WINDOWS\ERDNT\Hiv-backup> it is the copy system command line that does not seem to work

#53 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 07:07 AM

I think it doesn't like my backslashes. :blush:

copy system d:\windows\system32\config\system

If that fails, do a [b]dir[/]b and show me the results.
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

#54 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 07:13 AM

I tried the copy system d:\windows\system32\config\system and it could not find the file specified. And then I typed [b]dir[/]b and it could not find this file either

#55 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 07:15 AM

Sorry, didn't close my tags properly... we'll get there!

dir -> show me the results, please. (From inside D:\windows\erdnt\hiv-backup)
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

    Advertisements

Register to Remove


#56 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 07:18 AM

sorry, not sure what you mean by tags - can you write what the whole command line is (From inside D:\windows\erdnt\hiv-backup)

#57 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 07:20 AM

dir
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

#58 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 11 November 2009 - 07:34 AM

no need to be rude ;) Here are the results: From inside D:\windows\erdnt\hiv-backup>dir volume in drive D has no label. Volume Serial Number is 1403-B6F1 Directory of D:\WINDOWS\ERDNT\Hiv-backup 11/07/2009 02:04 PM <DIR> . 11/07/2009 02:04 PM <DIR> .. 11/07/2009 02:04 PM 290816 DEFAULT 11/07/2009 02:04 PM 673 ERDNT.CON 10/20/2005 08:02 PM 163328 ERDNT.EXE 11/07/2009 02:04 PM 1012 ERDNT.INF 08/31/2000 08:00 PM 2815 ERDNTDOS.LOC 08/31/2000 08:00 PM 3275 ERDNTWIN.LOC 11/07/2009 02:04 PM 28672 SAM 11/07/2009 02:03 PM 61440 SECURITY 11/07/2009 02:04 PM 38580224 SOFTWARE 11/07/2009 02:04 PM 10063872 SYSTEM 11/07/2009 02:04 PM <DIR> Users 10 File(s) 49196127 bytes 3 File(s) 12302602240 bytes free

#59 Raktor

Raktor

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPip
  • 3,114 posts

Posted 11 November 2009 - 09:44 PM

Wasn't trying to be rude, just helpful. :)

Please use explorer to navigate to
D:\windows\erdnt\hiv-backup
and copy the file system.

Navigate to the folder
D:\windows\system32\config
And paste the file system in here.
Posted Image
Graduate from the WTT Malware Classroom
If you feel I have helped you, please consider a donation. Posted Image
Topics will be closed after three days if there is no response.
Please do not PM me for malware removal assistance.

#60 sdabbs

sdabbs

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 12 November 2009 - 11:37 AM

Hi, sorry, silly joke (dir, as in Dir-brain!?) Ok, that is done (sorry for the late reply, I have limited access to the internet at the moment)

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users