1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Recovery disks with 2 Trojan.HBO on it...

Discussion in 'Malware and Virus Removal Archive' started by spiderpug, 2009/09/26.

  1. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    [Inactive] Recovery disks with 2 Trojan.HBO on it...

    Hi there, I got 2 trojans from my old external HDD. They caused a bit of damage, and I could not get into safe mode before but the trojans were gone thanks to the help of Broni.

    Then I wanted to format the HDD and reinstall windows Vista back to when I first got the computer which was saved on my recovery disks. With the help of Mattman this was achieved. But then... once windows had loaded and I was on the desktop I downloaded Mozilla, AVG, SUPERAntiSpyware, HJT, Malwarebytes, PC Tools Firewall Plus, and Ccleaner before anthing else. I then did a complete scan of my C:/ drive with Malwarebytes just to make sure there wasn't a trojan on the sytem... I then got 3 infections found...

    Catagory Items
    Trojan.HBO File C:\ProgramData\Partner\partner.dll
    Trojan.HBO File C:\ProgramData\Partner\Partner.exe
    Trojan.BHO Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Controlset002\Services\Partner Service


    so I stopped the scan before it completed because I knew it would be the same trojan I got before and that there wasn't likely to be anymore of them, and disconnected from internet. I deleted them with Malwarebytes successfully did a HJT report and ASAP quickly restarted the computer and went immediately into SafeMode.

    In SafeMode I then scanned with...
    -SUPERAntiSpyware(complete scan). No harmful software was detected! (with log)
    -Ccleaner
    -AVG. Nothing found (complete scan).(with log)
    -Malwarebytes (complete scan). No malicous items were detected. Log.

    I then did a HJT report log,
    and then restarted in Safemode with networking. And here I am typing this up.

    I am to scared to boot in normal mode so I will be in 'SafeMode with Networking' until its safe.


    Is this the time to make new recovery disks since it seems like the Trojans have been deleted and because the trojans are obviously on my recovery disks, and I should get rid of the old recovery disks!?

    I will post all the log reports in the order I did them in...

    Cheers Guys
     
    Last edited: 2009/09/26
  2. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    Sorry forgot which order they were in, but this was the Malwarebytes scan when I was in SafeMode..

    Malwarebytes' Anti-Malware 1.41
    Database version: 2861
    Windows 6.0.6001 Service Pack 1 (Safe Mode)

    27/09/2009 12:21:16 a.m.
    mbam-log-2009-09-27 (00-21-16).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 165478
    Time elapsed: 31 minute(s), 42 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     

  3. to hide this advert.

  4. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    This was the AVG report in Safemode...

    AVG 8.5 Anti-Virus command line scanner
    Copyright (c) 1992 - 2009 AVG Technologies
    Program version 8.0.401, engine 8.0.408
    Virus Database: Version 270.13.113/2396 2009-09-26

    C:\Boot\BCD Locked file. Not tested.
    C:\Boot\BCD.LOG Locked file. Not tested.
    C:\Documents and Settings\ Locked file. Not tested.
    C:\pagefile.sys Locked file. Not tested.
    C:\ProgramData\Desktop\ Locked file. Not tested.
    C:\ProgramData\Documents\ Locked file. Not tested.
    C:\ProgramData\Favorites\ Locked file. Not tested.
    C:\ProgramData\Templates\ Locked file. Not tested.
    C:\System Volume Information\ Locked file. Not tested.
    C:\Users\Default\AppData\Local\History\ Locked file. Not tested.
    C:\Users\Default\AppData\Local\Temporary Internet Files\ Locked file. Not tested.
    C:\Users\Default\Cookies\ Locked file. Not tested.
    C:\Users\Default\Documents\My Music\ Locked file. Not tested.
    C:\Users\Default\Documents\My Pictures\ Locked file. Not tested.
    C:\Users\Default\Documents\My Videos\ Locked file. Not tested.
    C:\Users\Default\NetHood\ Locked file. Not tested.
    C:\Users\Default\PrintHood\ Locked file. Not tested.
    C:\Users\Default\Recent\ Locked file. Not tested.
    C:\Users\Default\Templates\ Locked file. Not tested.
    C:\Users\Public\Documents\My Music\ Locked file. Not tested.
    C:\Users\Public\Documents\My Pictures\ Locked file. Not tested.
    C:\Users\Public\Documents\My Videos\ Locked file. Not tested.
    C:\Users\Spiderpug\AppData\Local\History\ Locked file. Not tested.
    C:\Users\Spiderpug\AppData\Local\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
    C:\Users\Spiderpug\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Locked file. Not tested.
    C:\Users\Spiderpug\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Locked file. Not tested.
    C:\Users\Spiderpug\Documents\My Music\ Locked file. Not tested.
    C:\Users\Spiderpug\Documents\My Pictures\ Locked file. Not tested.
    C:\Users\Spiderpug\Documents\My Videos\ Locked file. Not tested.
    C:\Users\Spiderpug\NetHood\ Locked file. Not tested.
    C:\Users\Spiderpug\NTUSER.DAT Locked file. Not tested.
    C:\Users\Spiderpug\ntuser.dat.LOG1 Locked file. Not tested.
    C:\Users\Spiderpug\ntuser.dat.LOG2 Locked file. Not tested.
    C:\Users\Spiderpug\PrintHood\ Locked file. Not tested.
    C:\Users\Spiderpug\Templates\ Locked file. Not tested.
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Locked file. Not tested.
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Locked file. Not tested.
    C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Locked file. Not tested.
    C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Locked file. Not tested.
    C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Locked file. Not tested.
    C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Locked file. Not tested.
    C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Locked file. Not tested.
    C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Locked file. Not tested.
    C:\Windows\System32\catroot2\edb.log Locked file. Not tested.
    C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Locked file. Not tested.
    C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Locked file. Not tested.
    C:\Windows\System32\config\COMPONENTS Locked file. Not tested.
    C:\Windows\System32\config\COMPONENTS.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\COMPONENTS.LOG2 Locked file. Not tested.
    C:\Windows\System32\config\DEFAULT Locked file. Not tested.
    C:\Windows\System32\config\DEFAULT.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\DEFAULT.LOG2 Locked file. Not tested.
    C:\Windows\System32\config\RegBack\COMPONENTS Locked file. Not tested.
    C:\Windows\System32\config\RegBack\DEFAULT Locked file. Not tested.
    C:\Windows\System32\config\RegBack\SAM Locked file. Not tested.
    C:\Windows\System32\config\RegBack\SECURITY Locked file. Not tested.
    C:\Windows\System32\config\RegBack\SOFTWARE Locked file. Not tested.
    C:\Windows\System32\config\RegBack\SYSTEM Locked file. Not tested.
    C:\Windows\System32\config\SAM Locked file. Not tested.
    C:\Windows\System32\config\SAM.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\SAM.LOG2 Locked file. Not tested.
    C:\Windows\System32\config\SECURITY Locked file. Not tested.
    C:\Windows\System32\config\SECURITY.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\SECURITY.LOG2 Locked file. Not tested.
    C:\Windows\System32\config\SOFTWARE Locked file. Not tested.
    C:\Windows\System32\config\SOFTWARE.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\SOFTWARE.LOG2 Locked file. Not tested.
    C:\Windows\System32\config\SYSTEM Locked file. Not tested.
    C:\Windows\System32\config\SYSTEM.LOG1 Locked file. Not tested.
    C:\Windows\System32\config\SYSTEM.LOG2 Locked file. Not tested.
    C:\Windows\System32\LogFiles\WMI\RtBackup\ Locked file. Not tested.
    C:\Windows\System32\wbem\Logs\WMITracing.log Locked file. Not tested.

    ------------------------------------------------------------
    Objects scanned : 342490
    Found infections : 0
    Found PUPs : 0
    Healed infections : 0
    Healed PUPs : 0
    Warnings : 0
    ------------------------------------------------------------
     
  5. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    This was the last scan I did in HJT once i scanned with, superantispyware, malwarebytes, avg...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:22:26 a.m., on 27/09/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Safe mode

    Running processes:
    C:\Windows\Explorer.EXE
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=1409&s=2&o=vp32&d=0909&m=aspire_5536
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=1409&s=2&o=vp32&d=0909&m=aspire_5536
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=1409&s=2&o=vp32&d=0909&m=aspire_5536
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=1409&s=2&o=vp32&d=0909&m=aspire_5536
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
    O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
    O4 - HKLM\..\Run: [VitaKeyPdtWzd] c:\Program Files\Acer Bio Protection\PdtWzd.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
    O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
    O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe "
    O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
    O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe "
    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe "
    O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe "
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\Program Files\Acer Bio Protection\PwdBank.exe
    O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\Program Files\Acer Bio Protection\PwdBank.exe
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
    O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
    O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - c:\Program Files\Acer Bio Protection\BASVC.exe
    O23 - Service: MyWinLocker Service (MWLService) - EgisTec Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
    O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
    O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe

    --
    End of file - 8230 bytes
     
  6. 2009/09/26
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,889
    Likes Received:
    386
    The jury appears to be out on Partner.exe judging by hits on Google - I suspect it was a 'freebie' loaded by your computer supplier.

    If it is in Add/Remove Programs uninstall it.
     
  7. 2009/09/26
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    Google adware. Possibly from the Google Toolbar, updater or Chrome. Has also been reported on Gateway PCs.
     
  8. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    what?

    I have already deleted google toolbar and google desktop when I first loaded windows....
    what does this have to do with it?
     
    Last edited: 2009/09/26
  9. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    My computer was booted in Safemode last night, but now It wont boot in safe mode.

    It just stops loading at
    Loaded: Windows\System32\DRIVERS\Storport.sys

    Then loads a black screen with the safemode mouse... then it Restarts itself and boots in normal mode?

    This is so weird, never had anything like it...
     
  10. 2009/09/26
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    Ok, at the moment, just downloading microsoft updates... maybe thats a problem because I haven't downloaded any windows update yet..
     
  11. 2009/09/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    So, what are the current issues?
    There is no reason to stay in Safe Mode.
     
  12. 2009/09/27
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    Hi

    I can access safe mode, all it needed was windows updates to be downloaded.

    But I have another problem now,
    I used Killdisk and deleted the recovery partition on my hard drive and I cannot get into Acer eRecovery to make new recovery disks...

    I need to know how to get the files back because I formated the HDD after deleting the partition and I dont know what to do...

    Really bummed because i didn't know I could have undodelete the partition I wiped with Killdisk:(, but its to late cause I formatted HDD.

    I got a quote from Acer to reimage the disk for $139 but I cant afford that...

    U have any suggestions,
    I keep digging deeper holes with my inexperience with computers lol
     
  13. 2009/09/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well, I think, you need to repost your issue at Windows section. It's no longer malware related.
     
  14. 2009/09/27
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,889
    Likes Received:
    386
  15. 2009/09/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thanks Pete :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.