Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

New Member


  • Please log in to reply
12 replies to this topic

#1 patty64cakes

patty64cakes

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 07 April 2012 - 10:57 AM

Hello, I'm a new member to the Smart hdd virus club! Hoping to find direction to get my computer back on track. So, I need directions to the right topic to figure out what do to do now that I can't find my temp file, to restore my files.
Thank You for your help!
Patty

Edited by hamluis, 07 April 2012 - 11:47 AM.
Moved from Introductions to Am I Infected.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 07 April 2012 - 04:28 PM

Please follow our Removal Guide here Remove Smart HDD (Uninstall Guide) .
After reading how the malware is misleading you ...
You will move to the Automated Removal Instructions

After you completed that, post your scan log here,let me know how things are.
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

Also the other tool log.. A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
Copy and paste the contents of that file in your next reply.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 patty64cakes

patty64cakes
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 09 April 2012 - 06:41 PM

This is from the 4/6/12 when I ran the program, unhide tells me the smtmp does not exist and unhide can not restore your missing shortcuts. So, what do I do now?



Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.06.09

Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
:: HOPE-FAITH-LOVE [administrator]

4/6/2012 9:55:32 PM
mbam-log-2012-04-06 (21-55-32).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 764375
Time elapsed: 44 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 4
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FoxTab Media Player (Adware.Agent) -> Quarantined and deleted successfully.
HKCU\Software\hblitesa (Adware.HotBar) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\HBLite (Adware.HotBar) -> Quarantined and deleted successfully.

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|O6CLY0MsAItyfc (Rogue.FakeHDD) -> Data: C:\ProgramData\O6CLY0MsAItyfc.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\extensions|HBLite@HBLite.com (Adware.HotBar) -> Data: C:\Program Files (x86)\HBLite\bin\11.0.323.0\firefox\extensions -> Quarantined and deleted successfully.

Registry Data Items Detected: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and repaired successfully.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and repaired successfully.

Folders Detected: 8
C:\Users\\AppData\Roaming\HBLite (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin\11.0.323.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin\11.0.323.0\firefox (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin\11.0.323.0\firefox\extensions (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin\11.0.323.0\firefox\extensions\plugins (Adware.Hotbar) -> Quarantined and deleted successfully.

Files Detected: 9
C:\ProgramData\O6CLY0MsAItyfc.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\Program Files (x86)\FoxTabFLVPlayer\Uninstall\Uninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSAAbout.mht (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSAau.dat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSAEULA.mht (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSA_hpk.dat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\ProgramData\HBLiteSA\HBLiteSA_kyf.dat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HBLite\bin\11.0.323.0\firefox\extensions\install.rdf (Adware.Hotbar) -> Quarantined and deleted successfully.

(end)

Edited by patty64cakes, 09 April 2012 - 06:42 PM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 10 April 2012 - 09:47 AM

Did you run TDSS killer yet? Do not run a Temp file or Registry cleaner .

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE
  • Double-click SystemLook.exe to run it.
  • Vista\Win 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box into the main textfield:
    :dir
    %Temp%\smtmp /s
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 patty64cakes

patty64cakes
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 10 April 2012 - 04:32 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 17:30 on 10/04/2012 by
Administrator - Elevation successful

========== dir ==========

C:\Users\PATTYB~1\AppData\Local\Temp\smtmp - Unable to find folder.

-= EOF =-

SystemLook 30.07.11 by jpshortstuff
Log created at 17:30 on 10/04/2012 by
Administrator - Elevation successful

========== dir ==========

C:\Users\PATTYB~1\AppData\Local\Temp\smtmp - Unable to find folder.

-= EOF =-

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 10 April 2012 - 08:20 PM

Hello. Ok this is a bit harder but can be done..

Please See the guide here .. L@@K
Scroll down to "Method 3 - manual"

Edited by boopme, 11 April 2012 - 10:22 AM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:09:40 AM

Posted 11 April 2012 - 05:47 AM

If its windows 7

Right click on your startmenu-properties

Check mark

store and display recently opened programs
store and display recently items


Click on customize

Click on Use default settings at the bottom

Now go to

c:\ProgramData\Microsoft\Windows

right click on startmenu folder,click on restore previous versions

Now select a snapshot before you were infected by the rogue,click on restore

You should get back the startmenu programs

If there are no previous versions available follow as boopme suggested

good luck

#8 patty64cakes

patty64cakes
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 11 April 2012 - 06:33 PM

Method 3 in the case the program link shows empty, created shortcut still won't open the program (Microsoft Office Home & Student) msohtmed.exe another thing I found today you can't play any microsoft games solitaire,hearts click on them an nothing happens? Could not do what narenxp suggested no previous versions. What would be my next step

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 11 April 2012 - 07:46 PM

Hmmm.... Try running this script

Windows 7 64-bit US English
http://download.bleepingcomputer.com/grinler/fakehdd/win7-x64-sm-reset.exe
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 patty64cakes

patty64cakes
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 12 April 2012 - 04:48 PM

Ok, the script still didn't work.(should anything appeared in the black box when this was running? nothing did, another screen came up and said you could now reboot.) I still can not create a shortcut for Microsoft Office that will work. What should I try next?

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 12 April 2012 - 08:22 PM

Looks like we need a deeper look. Please go here....Preparation Guide ,do steps 6-9.

Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
Title suggestion... Missing files
List what is missing.
If GMER won't run skip it and move on.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 patty64cakes

patty64cakes
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:40 AM

Posted 14 April 2012 - 12:45 PM

ok, I was able to do step 6 with the following results


defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:40 on 14/04/2012 (Patty Brumfield)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

Then I moved on to step 7, and this is what happened, I didn't see any of the examples in the step. Sorry I just tried to copy a small sample of notepad that came up without seeming to run the program at all.

MZ   @  !L!This program cannot be run in DOS mode.

$ 1:uiuiuiֵiwiuiiַidi!iiitiRichui PE L K   P   0   @               `    ` UPX0    UPX1 P  F  @ .rsrc    J @ 3.07 UPX!
 $И 'C & "U\} t+FEu
H
>Bl HPu Hr@  uS݌}V5EWPLel1E P}Dp; FRVVUu+M‰M3ҊQNUM1Tv>PE3m sPBprEP T޾9}qw ~Xtev453tn۶/jW: "͹* )XWKpgXh -PgWjh6%Xr 9Yw\_^3[_L$FSiAVWTtOq3;5sBi}YDGt /BOt 
u 3ڃ9ٴ۳F1Art[w7QQUi{3W?BF^~ 9M t$B;DiG|B
,R#u(@Ewt ;Ar7
͈,l t/N@狀?? V3 s49v,P $uGzt ~^$F[? seZmB=#+39tK;sEr5db(p۠<@w#ȋ;vCxw[w{rt
V rmCDN}@m @e
+Q;Jqvt$jxkt]8C\P!0=k iCu@FH+&|$ /{jv7{w5th0u
u0qu/PheDޯa{}^[|'Ctljhps˝? Qo8^Mʡ"JWjcY}NKcm
]
M܉
hM؃A׷$(S?(
ll߽9]c
!S9vBH-9w_S
ՃP8-׈|Fܿ-
^u" ?s7y`<-k){/4a;#ǶC64VÆ[ /Wp]`xl7+tRQ%ǜ<>[j=V}ຄ=!XWF_f;tBj\V
SWE c:u |=j5ۆW
x,{'F:utjBwmWh Kb.t<>j`SnN]co vjj}E#WVpj<1o?ؿfk
WHjani M~Po:Hl#;v%8c!C;t,`Vv mD#6I7WhdB{QVzSmd>9o,jh
j1VuckzFVpVYI P"wK~MĿp}|1ʸm]Qw7i`
р#\ouu5Ch$@۴19uv(SF@WV
-EZ1WPPD#6/еS'HVj<lN/js|(fTSSzu
6(^
Pߌ;$~ujV`~j~%hR pS4
['PYVjiD;J򴹅Ww21' zsKxj!j6G0 nԷJ}td*[woh37;~vx/sUnoc}x,ysoC7MN: o1vIRp5")WN)KPOl,6wV?]
yB m9{KOo-n;|~sov'',Jռ7 wm腥)ޠ b+^ϋ- lWЖm/J F#B3>Z04[v+u+ t/>
8 E&9ٽW]P -p}DH|?u
у #W.]KVP;t%}8
.GW6<d'hj@pF.GR5ƘT \!˄3 פD8Cm!uDM'fjjUkɆf`q?D,E/F슇f5v1Q#/-v
CY&h& FPg6ʭs(rQT1&N%,J8pg&A0Rq/*.iv\5. j[ m0 SS 5븙4hr)VOf| P HjZf{c\8.@PS*t\ ?F
6Fh m8B))6nއlC `
<S [\X

8jҥbpؖ訐Z%
S#p\[K!hu
gDpHVvUp~C)T,z8F9njjd=p'[m[t#(`b
0JŶ $$yaZps:ꊱN}Q6ZP`k8!a7̜ؐ jƈ456J4n0N@DTp܄ |& q9Xs܌U]͎o
q[wjStzOW:=ketVW8Ab1ī+(Ԫh(o=
vLjJ=ʓ&K
|rqj6ؼ߲,gCl E" VDb!sܒ@^rq,D۶w뾄Rh)QLѷb<.$
-!K-:QR<+ܣl@R4)pߖU#>0ٜQDr ,~}|/hImoN+&п_#h@3q^̍=g
Gpd>[Ih4;nu
Sj^uOW\u0 8vf-+fM'hc@7o`q4B,=
t-j *p"g 943V `:8 ht
"RcfW 2Hv!N~ Bh V"ll$kVcu+n;ʟ.lѺ;VU uQ=R:2a`udX͘#S]
P
S UV"Rw2<PЪߓp@V!XRMouc }SεU
:^yh BC˶9V͐GQVQD n+UAG4t9WtuI~O%0q6k 8C
gVmv#\[Uw3''4uY QVu'A8;: &d׌Zup8K:\P&5jӈ,>0
6Xs0c.$(]Զ  3Do>;~̟ v v] >~}:(467Ե08zЈJ$,eZdx_ru!}
t+ou
)>st@;|9wlPM>$]8<6<
u1Bc4t|>|lXtLSm4ؖ!aNf-."8q웵t\i< 1Hpu?Ybq{,Q#EfD1w"+قSVV:
D$f@6h=ub@dg׻`DWW5pV?{g!w!C]:dV#MuЀTuQQX]MG#W&{ЯQG;W`K»Hj^}^2`DV@҃V5n_{| ,Vo=¬mRQt+ȺYj Ed%DN '_MBȥn,y ~O;J$t#XAcȮXQ"/c]:A;дe%V-+Qj́WsTpr@ba?# Ml֛f4g45Ml9ZEYvn!4Ͳ
"4le&XYmLus 6P r!#"lM#'$Y6M%4˦&>|}'3u`fy}4MM4M@2h4j?0gPlW}ďȠm%*N.ؙB''/R}WSRA *WP 3]-* >i
=( @,d^huKΚ"JW1>uqcN$5hHjbB$~c3 "u>ÇDG
$ ɠ( ):Z;p8EM0#']mX@} Ku9h4v !8NJ=6[8u;Yp<?3C h?=D9
@pA ·;|dQ×692 ȡL(;"`诈5v9Y f&j
dXt-~tGhP&~B?R#Vh;+]jo=ojP1i^;(ls/W|~q 
Sxcc,=B
t=
V@kV,P3V0h ^5e@Yp~% ~yRW>;mW\.u~j]P*/M;uqᆳuhInstu_sofVNulluM EZW(ƒ \c
_/kF@"9/DBp;vÅ\SY;5
=i}SNnS=_+,!0YWh*(/
j}򨄌w6U?k`O^jjЉ
%m*;ph0ؐ0Y=PcKqUU֮rјT+J.pVTDEHݍs޸`TƅA設>ʼ DY0I@D<nc]0F<T $z w(EW|w$WWD5j?&X3^o ?(6`gj,,TI,wQ`5N>>A\h |!})kx+ݾ@0" }+ZapY?tm;}wodV 7ula`)Es3 0jS3T9
jm|Z)2[:4F1zjXk*gUOUQ+x#&tzchp[; nTBx&1Kcω@.c+9LF`[^@R=h t)@<!0SGx~kc։-rˮdO~|{+t2$̶n<SUfϽ U;O|k
j
&=u73}o҅+
&L-ɣBW :҆n
', 3][Y~ , ÐA{2,
9e3
k  ('NgH;䶱V^ U2V2M;gfƀUǃa\y6m  10hAd68K'|p$L#գ@AM4h`KnӽXAXhKQ:oj'jHeS@="Ǫs
|"t|o |c X@8 t".}{6/u3SuH +8NCRC[Vx /D=eiQ[u@:uXb0HfUfЬk" hQͳuUHU"t~yD6Ônpue4x6M > _?N;sfztrdSG6Cn*V
]Wz
Li%fɝv%pfAV<DpFDUtf4,Gt8Yu N7Z+=jf[
_UX] oHVt?Y(&p-S-,W6$j́Pc_jOu5R $$9t{ 4љtHD@˽j(T][Մ,$ǧS(lth08D f$v ;"M8t i{

oָסEej!mW<\-2pZT;V6Y
vRum۱:%t.lw._%<}* OM HMV
|@N3hn~vVy
J@,j Ps_3 pHH^):1mC+Wj}fU*luJ[WR9N5MhJ0x k"I}!u#hs"]'hWK⑃)tMn3/ UO<\hRx Q2NHzVL3@.]؇vD{]:T<.A V<w3_h#%8yv&h76PB5Wb[vb Ue
׭_jgTC6~a5µ
w|`6TW_N65bD6.
P d^fllj0^ Sk9hqq i
0(POHhx21OID.\X)l^kmpa*Ƭ`
-:5B
#vWUIhlֽ-ȡs/
SihE:
T7B.{ +?ұ[l6Np'5 v(,  W`(mffiEDId
Nf)f3#mojzQ]oXHQ
uf%m`%|h1!~X^E=D}⋅"LP0V)Õ
\mf;W
;% /|3G9U Wp`Ǜu,H#n
PF
u0g6+^.xo>uRx (t0rz)bt/h %DoȠV.5X^ȥ-đ~^ _Pu47,WmhM*x.POJu%1a/{b?G/{߯u2KMckkֈm#W j `)}j?Yjр3<bN/<Ў5ޠ;|>u1Up"U$o$Z[DLZ'9.
 (`c_e Z_wHC997s{/
$^P Ƹ@b
hA($y(hzK- F; W`U˃,)%Px<PF6R;tUAeh|grx*`lO 8=AeO҃ߡfI7SbSprg Ҕϥ--t9dsDmg Hnw6vm#L<Ū>4wXBfFWG|[;hovK#y`Z,rt|pe5 U Vψu\
ÜKT Nbl@q^isx6j
WCzpzv(J\*,x5[
h>d C">)5 PO ! -4<N MKMd{Pv N&VQ}FP5܌A}@ߝ P9נ%*_.m)g<0!(=Cu$ H8=:Z[GdQ?F;c|M J!4]n6
1y$ L
 ]{0}M#+ȋ92s4pk/)C؃e
G}ۅM,@} s8j#*Z* ~8
ZPt;h8 DzScDcmh[47 @h bv~$hCRE&߄d&5㰭RuI&6&!2EuZh׀T.s3
*
ōy \ňo-æ$mٍP ȉnNF -} er iOW7+ʁ %Up?sLMQKj=s~F`kuE\c <
( Pz KɯuB
Јt3D+0FN ]B|"F%SWxFDP=$t(u(3Vu&T0R <50P;Nƀ
Vl^Hjp<DB%h8 7=M@WuE
VSH KaS[E<tk]^=b-\p4+
0j8$j<5n,=z9!3τlԋA,=* ׆- $|{hpE[v=PuRHݶPATc VPwN{S(@+ VP<WW[Bl~Pst
Qu [: Ah.̨&vCS7
4t5t-Ad"];lۢf!Q+]Zf\EAJH' qP";P:Ѿ Cpxf0-#U $~

0
v$ 9j7 ;sx <9Y+Q>;}'6WjV
VL
GãDL
A;Apt2\uFU:p 9q%} i4Lp:00
Vf(u-@8F[]Re2@[T _j[s8[1sj3 3V @-YhՄnύjߠ-5S
% *I3ҀYN
RVh'@W,TOi*oԋV>
ȋt'A

PJpXu8FWh\C. fap8<2 cv&@
Bp;3Al BPS,h0\
g 1AwBXpR4L"R.RH wm}[RcĆ]?jn\ѸT
\hTN!n
v:j!C+`43Ep|( 5Sh Wm/4l }
IrZ8BJ' 6^%AC/Q uvC'!|ɹtpC6v
u,=TNğaSB8 dժIYn^#ѣC
c328ʰMэ ؓqS:(}.tSjV*KLE>73'Q }G=KǶc:.$Ah-[4 "u!ӽ4&68>;&(mQb4 tA B~sn6syk5[v+9yuhT6V=Qs7SȨzBT
Ėj~@TCwńy
P
taWHPФ[G#9t7N
xnn,\0Pj(xڞPmV\DibsY\#RiMf OlH^=8D Gc#Pwl49<^X[[S g# 9~s][q"z ^Në2[A_!w,͔d{_]}= g7SGTx(t[Syt?Y{0 T2W~⻽tA@SWQhN+
&VT bg@y{0yKM
XYno7t )ԽC ̀c4Xml4-oK 6: 8A+Rh
R qGWHOgWD@2x
4$$ 56S,M Eɗ Wh6!qjouL u}h0U>w|SQBeZ
;NIt3WEcƪXCV+
_?S]Y4wm!C<0ҩJxqQu CCM% l =-Cbss~@&Z`b6DSZ04_ ~+ǔPDsw]P%3Os
t  o\V^" | x wj OFf6a
Զޅ `#6l T܄f PlAY!K}aB!(Mh }'+q૫=q,|H\`x,`d h霩t?0hTzw2t)Rs6TXYC̼xBr+,Ua6 U6f|&
& Y/|$!qybf0t4Skm

ţlkv!2շ Q@0uSX@fk΁ $6ή tC$'f;(h֯*<O,8  Bu6b];ֲZW[Ut&jx։,m7S

6"zV ;Aj
n{u4D FfMQj;Tģ\$ 1:Pak6m\j3;Ŗg^ u##,-&0Mu\(tS#>[ }jBPGfpfԏ<bf
FFC;vߣ3[sn+@gLBv.q$D޷h P 1TFtW4%qNktUP0 YG@l/46uG
HZWu*Gu; @A>
c_H|WuUܛDqeF5
Os]@+>3A ! 
hH 47wƀaр=(\u DW à+0} fj?P/ᨣcٍuۅ>.uFuh<
~%b#^VZ[<-N+=WZ pاH"[gmL4R[<z[ntMG@W >T9Yp V!1ӴPO\td'<rV^O


:L/R>uF> KB\w;@AVLȟ9\" <a|
<zmy:%Z>%&Sz |T8;:b!D?u8 ^j\PN@o;`VJ0'brL86sR'1t
!lu<+c,F ѭ RJVWW'*s{Z#3xx7"7$7h#{PNc[}Կ=47VBw~+JANu^' En
$hůAPWQj bѡ?
+d_Onsa܌33X(V~*d
n
OЀ& ];^[Q7+}Vj9MhpZnk0&B&ULU4޽a0UJWl/@ŏ ;_> X .UhT$,^& EaoTf(h']Eփ>lK/*6UǍD=0
oD<UQnۇ[;|uy s/_Z>P}
),P9QE43UW(n2ٳo]#
hPYkt@ >;s U +E;r-4,t+SFP(De
JX?8K>x,ߥIV  6ru tA1(@;F" : QQz9-Ѱ
ArHA0| 7F XuAֵ( ;0<oo!߃A|F )$)$f[ MZKS-1vp%}'T jW_ȸM+Ӂf:}"=V'M+AM mEA fq/< 6π[-J ̀7ZъTY0`yf=Zj#>Zt.JH7%$% y7\?q@Ps@nd_x) %>U萷fq$uhHh<GXTNB)tWQѯ\t8
,XdwAD[ă/u'޲! Hs XD#uj6&Wa,W[i!&s2fE@O3D,l߃oJ
#GAL,\
&䑵Vd81 n
Zt8ZWomdj?+ AٍߨJZޑt9{-$<v"\Lup[դFW5\ m:;9$
u]Ǎ
< t6pMX$HB@tʼn85OoW "01q`:3
$=
x0~W4
!A0TfI4*^UVu-0~V^ ҁt3
0'Aؾ|T'Ņv#W9/EƋ423AmJ_&C_(t HuIxE˲݊Ahd`\ "7Y$޵pШvDmtY鬋
~!H
:Wi֔ maՐ#%j-dj Y
1׾o҉}BJU
wx7 cƣ6<6;}9; 4W" 3yjO[5 NJpdla&ܷvvn E}%|;Et(bm$]v"ہ.x WAMuUAdeo!EMlrj  n[ǘ ##7.Dž|^D"tˍ4HW,U[!/,o`/*#JlV4/xض@_ x?lJ-&}IȪ[ 
}'mJhtFr
BC.Eh
uSp,Z̟Hg1g;ae9&VK ׽3Q
!
Υek9ф3`A( vA]so+ʰf)mO׶0f>.U\}m qøgQƺ}ܷ\@&{τ͞dZ sR̾8l x?hUxQF u 9TQhSCu'gh.'.4!,Y탕  hH$6bdP#N oN%.4 Q~;nF\
Bḻ?;WjӃ/' lwM@f%x`'O6rr & F)M5,MM >7
Eh
!@g.$C VK Э4P-\6+{'`DX^*4[B[%IrwU+~1Bz{^,\ۃ޸yW3R
m(i ~'7Zem;cJ8FrkXփbsýpD0 ,(!P۳}r LOh 4_^9UUKe *)xsmA㋹L$ (%G60)Ɉ$U|T]لtK4 9+<5,|mXy#;ѵ QT @k-ce#8E7|pϞXWp &y( $0|xk<pz%/s%Hc95բSt z$Js{~
&0E2,^MK`r- |BU mlomZ+[9`+ф)ض

@saY|
<'pdXsL@C=' 4(+l" 
FNT.bt,x&.tL#o_p`f[(agf\61ac:d}m,ebslGXf#(gg$hf5KiOfbhq뺔 +'gp fFrlh WRichEdit `20A32 .DEFAULT\Control Panel\I { ernatial'Desktop\RourceLoc&e' [1me]
%d ware\MtZw[?s
\Windowsq9sUVhsf;#? et Explo&r\Qukk Laun+!F n 
ID`1"$wD+@ ]3Em6\ veorifying stall: %d%%#~unpackda þde. I9owCtegPty cheohas faid1Commonauskes)clude
p 7` tnload andqmang6 mia<Yt ɶtV
'FL}kowto ob new
dopy.

Mifo`m*.t:
http://n_sis.sf.t/NSIS_ErrZ{X w7arfȊMakTsu[tYy[oamldviCl]۾vGeShPcvT ~u.tJ\Te `@@;HCBP n.exenU%E%s(
g<i>( 4Լ<4]Ӡ|h]aGLF
PihA[FOLDER AoCALWAPI 5Us3DÍۍe*ul
IL guB?3Adj/tTos,[LoupV][uepOp(oc$s4O [rKeyEx%ADVvk[j"FBDQ(\kFڠmKNEL+\*.*
[-mgs=D*?|<>/":BB$?FT @P2
d@(
Q  *@FTP2
`@* HʀM S h e l Dg` @ 2  lUDPdy    ne@
X; 
{ @EP7 m s c t%uݿ_ p r o/r?s3\0 ?q@@ mnyGL ie VYwWu  g%’# <f;lGȚO-E̺1"B"X.'``WAzarvTimeSechGetShortNa"Full
7/SnO"Dict:y2~ttributesLast5ʅ,
Oe3SSep:ckuf_:+iSize lYmdaDepy>Exi%$se)7mandLinoݝ,Loabral Pbn7k0MlobalUn,vX
L ThZlXd
7R`/$veІm/y n?Yky
(:77*hseH97SiA
ݍ%pEnvA0솆mJSngsAlYWaFbmlS'WObjzv-qJdشpAM-؋-Addr1m#9tiBy7oWiVvCh|:ivl{Af!M;b!5MlѺY _D-PBko+$b 9,
NexB\TXv,-aZ wgQu^y̽zl/$umKey  Yl6*{,fl. f1q="(jʍIge_M:^kedS'olAKE/<Bor_heLCaps
c#9BrushI(C$}ttAR
T3_SPctR79xbTM Xh팮O$LiU
<U`.uٗ{6ncCPaHnIIDHRDئr nV,Efoh1W+ll_0SkxrL0̵+ El1OlڮdDgcnTԴ`R6Z)ab`%Im/`
Q͎JTcIs;15ds<fK;d s CckDlgBtnb(S+BQt8p+loNVaim`pb7r
&D&aty!1S{,<Ox+wTrazpupApa|M2d Ag /&c%vzMqFBox۫^p肕her'P -[k
QƄasmlr[
|TtBicmGl QuoW;&SwtfJ7{,R%ElB+I|,S̙f 'GNfNKxͧ,

Xo ]rA;rCA6<,N
+O'gflBeg&iiFQ8
5l Djf
3-2wJinZhCgAs
AyVlPEL K5   \k{0`L!p@ Z;i<(XesX]-
W..t`}vZZ# 0.9n'`@.& ,Kr').n(#@+Tx' lwv V  ` B `W FGur usu s1Ƀr
Fttuuu Ausu s /vBGIucwL^J G,<w?u_f)ٍ   tE_0` P Gt܉yGPGWHU t(   PTjSWՍ `(XPTPSWXaD$j 9u{=   8  x    X     P   h    i j o             `  g 0   H     p               ( @   33333333330  o  ox   o xx  o8 ? o 8Ǐ ?̏ o8x ?̏ 8x o?̏ x ̏ o                              @        X 4 V S _ V E R S I O N _ I N F O           S t r i n g F i l e I n f o  0 4 0 9 0 4 e 4 X  C o m m e n t N o n i n v a s i v e d i a g n o s t i c s c a n n e r 4
 C o m p a n y N a m e S w e a r w a r e T   F i l e D e s c r i p t i o n D D S , D o e s n ' t D o S q u a t <   F i l e V e r s i o n 2 0 1 1 . 0 8 . 2 6 . 0 1 0   I n t e r n a l N a m e d d s . e x e .   L e g a l C o p y r i g h t s U B s 8   O r i g i n a l F i l e N a m e d d s . e x e ,   P r o d u c t N a m e D D S D V a r F i l e I n f o $  T r a n s l a t i o n  <?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly> h    u  0   8   @   H   P   X   `      
 
 
  ,
 8
 H
 X
 `
 KERNEL32.DLL ADVAPI32.dll COMCTL32.dll GDI32.dll ole32.dll SHELL32.dll USER32.dll VERSION.dll LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess RegEnumKeyA SetBkMode CoTaskMemFree ShellExecuteA GetDC VerQueryValueA

#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,492 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:40 AM

Posted 14 April 2012 - 08:08 PM

Wow that was ugly...
If you cannot get DDS to work, please try this instead.

Please download OTL by OldTimer and save it to your Desktop.
  • Close all other applications and windows so that you have nothing open.
  • Double click on the Posted Image icon on your desktop.

    Vista/Windows 7 users right-click and select Run As Administrator.
    If you receive a UAC prompt asking if you would like to continue running the program, you should press the Continue button.
  • Under Output, ensure that Minimal Output is selected.
  • Click the "Scan All Users" checkbox.
    Leave the remaining selections to the default settings.
  • Click the Posted Image button.
  • Do not use the computer while the scan is in progress.
  • When the scan is complete, two log files will open in Notepad:
    • OTListIt.txt <- (will be maximized)
    • Extras.txt <- (will be minimized in the Task Bar).
  • Both logs are automatically saved to the Desktop.
  • Please copy and paste the contents of OTListIt.txt and Extras.txt in your next reply.
    If the Extras.txt log is too long, you may need to add a second reply to your thread or upload it as an attachment.
  • Click the red X in the upper right corner to exit OTL.
Important: Be sure to mention that you tried to follow the Prep Guide but were unable to get DDS to run. If OTL did not work, then reply back here.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users