Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Restore


  • Please log in to reply
8 replies to this topic

#1 np63om

np63om

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 04 May 2010 - 06:33 AM

Hello, i use the combofix, now i have problem,ERRO: DLL: c:\user\user\appdata\Local\Temp\sshnas21dll

i try to restore the windows to early possition, i canīt, the restore is disable.

know i have on local drive c: icon Combofix, when i click there is shows the local discs or drives

Please help i like to know how do i restore to early time, before i use the combofix.

i donīt what to use the recovery cds, on my acer, the reason is: if i use the recovery cds, it cleans all i have on local drive C:
:huh:

Please help.

Many thanks to you all.


Best Regards.

Edited by np63om, 04 May 2010 - 06:58 AM.


BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:04:18 PM

Posted 04 May 2010 - 09:42 AM

What was the issue that you having that prompted you to run a program like ComboFix?

DLL's shouldn't be loaded in the Temp File Directory, therei s a possibility that you are/were infected with Malware, and the piece of malware is running and requires that DLL to be ran.

#3 np63om

np63om
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 04 May 2010 - 11:31 AM

What was the issue that you having that prompted you to run a program like ComboFix?

DLL's shouldn't be loaded in the Temp File Directory, therei s a possibility that you are/were infected with Malware, and the piece of malware is running and requires that DLL to be ran.



the issue was to check if i have any kind of virus, and it found the robokit, after check all computer it made restart and start bluescreen combofix, then finish, and i restart the computer and then the erro dll came up.

I try to restore the computer, using the windows restore, and i check the restore section is disabled, and i reactivated the sistem restore on windows vista, before that the restore system it was activaded, but after activade the restore, and try to restore, on that it tells me, no early restore point found on this computer.

by the way, many thanks for your help, i gonna run the Xoftspy to chek what you say...

Best regards to you all.

Help please, how do i restore ths system using the combofix, the combo mak regestry backup, how do i restore the system using the combofix registery backup?

Edited by np63om, 04 May 2010 - 11:40 AM.


#4 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:04:18 PM

Posted 04 May 2010 - 11:47 AM

I dont know how to use Combofix, and as such I will not give advice on how to use it.

When does this DLL Error come up?

#5 buddy215

buddy215

  • BC Advisor
  • 12,878 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:11:18 AM

Posted 04 May 2010 - 12:22 PM

sshnas21dll is associated with "fake alert".

Use one of the free programs in the links below to remove "fake alert".

http://www.superantispyware.com/
http://www.malwarebytes.org/mbam.php

Post the scan log of one or both of the programs in the "Am I Infected, What Do I Do" forum if you need further advice on
dealing with the malware.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#6 np63om

np63om
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 05 May 2010 - 05:42 PM

sshnas21dll is associated with "fake alert".

Use one of the free programs in the links below to remove "fake alert".

http://www.superantispyware.com/
http://www.malwarebytes.org/mbam.php

Post the scan log of one or both of the programs in the "Am I Infected, What Do I Do" forum if you need further advice on
dealing with the malware.



Many thanks to you all, you are right it was "fake alert" i solve this problem with your software malwarebytes, one more time, thank you for the help, really was good help.

the scan log dont save it, sorry, but i may say it was malware, problem solve, for those have this kind of problem now you know what is, it is "fake alert" by malware virus.

Please do you know how to remove the icon of comodo, on the three of my local drive c:?

it is possibel to restore the system using the comodo? i mean back all the process before use the comodo, is that possibel?

My restore is blank, the comod make that, or the virus, know i see some Qooq, i think is somethig about the comodo, i guess is the local where the comodo save the regestry backup i guess, can you solve how to restore the system using the comod is that posssibel to reverse the "state"...?
Many thanks for the help.

Best regards to you all. :huh:

Edited by np63om, 05 May 2010 - 05:48 PM.


#7 buddy215

buddy215

  • BC Advisor
  • 12,878 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:11:18 AM

Posted 06 May 2010 - 05:50 AM

Download http://oldtimer.geekstogo.com/OTC.exe and save it to your desktop.

Double click OTC.exe
If you are running Vista/W7 then right-click the program and choose Run as Administrator.
Click on the button.
It will cleanup the system from tools like combofix, avenger etc.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#8 np63om

np63om
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 10 May 2010 - 08:47 AM

Download http://oldtimer.geekstogo.com/OTC.exe and save it to your desktop.

Double click OTC.exe
If you are running Vista/W7 then right-click the program and choose Run as Administrator.
Click on the button.
It will cleanup the system from tools like combofix, avenger etc.



:huh: Bravo. Many thanks to you all. it realy works. job done. :huh:

Regards :huh:

#9 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:04:18 PM

Posted 13 May 2010 - 10:33 AM

Download http://oldtimer.geekstogo.com/OTC.exe and save it to your desktop.

Double click OTC.exe
If you are running Vista/W7 then right-click the program and choose Run as Administrator.
Click on the button.
It will cleanup the system from tools like combofix, avenger etc.


Thanks for posting that.

Download http://oldtimer.geekstogo.com/OTC.exe and save it to your desktop.

Double click OTC.exe
If you are running Vista/W7 then right-click the program and choose Run as Administrator.
Click on the button.
It will cleanup the system from tools like combofix, avenger etc.



:huh: Bravo. Many thanks to you all. it realy works. job done. :huh:

Regards :huh:


Thanks for posting that it worked. Happy computing.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users