| | |
warms and proccess problems
![]() |
Ah- now that's more like it. Time for the Killbox 
1. Unzip the downloaded Killbox file to your desktop.
- Run Pocket Killbox, paste the following file path into the "...file to delete" box, click "Standard File Kill" and "End Explorer Shell While Killing File", and then click on the button with the red circle and an X in the middle:
C:\WINDOWS\SVCPROC.EXE
- Repeat the above process for:
C:\WINDOWS\KKLIEY~1.EXE
- Paste the following in the Delete box, click "Standard File Kill", click "Unregister dll before deleting", and then click on the button with the red circle and an X in the middle:
C:\Windows\System32\DrPMon.dll
- If you get no errors when you do the deletions, reboot your computer.
- If the deletions fail, do not reboot yet. Instead:
Run Pocket Killbox again, paste C:\WINDOWS\SVCPROC.EXE into the Delete box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File with be deleted on next reboot, Process and Reboot now?" Click "No".
Repeat the process for C:\WINDOWS\KKLIEY~1.EXE.
Repeat the process again for C:\Windows\System32\DrPMon.dll, but this time click Yes when prompted to reboot.
2. Once rebooted, do the following:
Open a new/blank Notepad file.
Copy the contents of the code box below into the Notepad file.
Name the file as fix.reg.
Change the Save as type to All Files.
Save this file on your desktop.
Double-click on the fix.reg file, and when it prompts to merge say Yes.
3. Reboot the computer, run find.bat again and make a new log. Post it.
4.Run hijackthis again, make a new log. Post that as well.

1. Unzip the downloaded Killbox file to your desktop.
- Run Pocket Killbox, paste the following file path into the "...file to delete" box, click "Standard File Kill" and "End Explorer Shell While Killing File", and then click on the button with the red circle and an X in the middle:
C:\WINDOWS\SVCPROC.EXE
- Repeat the above process for:
C:\WINDOWS\KKLIEY~1.EXE
- Paste the following in the Delete box, click "Standard File Kill", click "Unregister dll before deleting", and then click on the button with the red circle and an X in the middle:
C:\Windows\System32\DrPMon.dll
- If you get no errors when you do the deletions, reboot your computer.
- If the deletions fail, do not reboot yet. Instead:
Run Pocket Killbox again, paste C:\WINDOWS\SVCPROC.EXE into the Delete box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File with be deleted on next reboot, Process and Reboot now?" Click "No".
Repeat the process for C:\WINDOWS\KKLIEY~1.EXE.
Repeat the process again for C:\Windows\System32\DrPMon.dll, but this time click Yes when prompted to reboot.
2. Once rebooted, do the following:
Open a new/blank Notepad file.
Copy the contents of the code box below into the Notepad file.
Name the file as fix.reg.
Change the Save as type to All Files.
Save this file on your desktop.
[-HKEY_CURRENT_USER\Software\aurora] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\ZepMon] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Print\Monitors\ZepMon] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon]
Double-click on the fix.reg file, and when it prompts to merge say Yes.
3. Reboot the computer, run find.bat again and make a new log. Post it.
4.Run hijackthis again, make a new log. Post that as well.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Linux as well? Oh fsck, I really wish you'd have let know that before... :eek:
Not time to panic yet though- a few of here are Linux geeks too. :mrgreen:
- Did this happen before/during/after trying what I suggested in my last post?
- What version of SuSE are you running?
- Give us the specifics of your drive/partition setup and your bootloader configuration.
- Give us the exact specifics of "KABOOOOOM"; what (if any) errors you get, etc.
Get us the details and we'll take it from there...
Not time to panic yet though- a few of here are Linux geeks too. :mrgreen:
- Did this happen before/during/after trying what I suggested in my last post?
- What version of SuSE are you running?
- Give us the specifics of your drive/partition setup and your bootloader configuration.
- Give us the exact specifics of "KABOOOOOM"; what (if any) errors you get, etc.
Get us the details and we'll take it from there...
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
so this it how my KABOOOM goes.
I did what u suggested, and it worked just fine. what I did next was to try to fix my SUSE partition. I was unable to boot lilo. someone suggested that i do a repair for windows and run the following command FIXMBR.
after this was done,,, kaboom happened. even my windows stopped from booting.
I have a 30 gig for Windows
55 gig shared
14gig for linux /
12 gig for linux /home
and 1.5 gig for swap
I am running SUSE Pro 9.3
I did what u suggested, and it worked just fine. what I did next was to try to fix my SUSE partition. I was unable to boot lilo. someone suggested that i do a repair for windows and run the following command FIXMBR.
after this was done,,, kaboom happened. even my windows stopped from booting.
I have a 30 gig for Windows
55 gig shared
14gig for linux /
12 gig for linux /home
and 1.5 gig for swap
I am running SUSE Pro 9.3
- Why did your Linux partition need fixing in the first place? As much detail as possible about that would help.
- If you can, give us the details of your exact partition layout (/dev/hda1=Windows, /dev/hda2= /, etc.).
- Did you have Lilo installed as your primary bootloader? That is, installed on the MBR (/dev/hda) as opposed to the / Linux partition. If so, the FIXMBR command just wiped out that boot code and restored the Windows-only boot code. You will have to boot into Linux with a boot floppy or the install CD and re-run Lilo to get your Lilo boot menu back. I can tell you how to do that if need be.
- If you were booting between the two OSes in a different fashion, please elaborate.
Get back to us with the above information and we'll go from there.
- If you can, give us the details of your exact partition layout (/dev/hda1=Windows, /dev/hda2= /, etc.).
- Did you have Lilo installed as your primary bootloader? That is, installed on the MBR (/dev/hda) as opposed to the / Linux partition. If so, the FIXMBR command just wiped out that boot code and restored the Windows-only boot code. You will have to boot into Linux with a boot floppy or the install CD and re-run Lilo to get your Lilo boot menu back. I can tell you how to do that if need be.
- If you were booting between the two OSes in a different fashion, please elaborate.
Get back to us with the above information and we'll go from there.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
/dev/hda1 is my windows
/dev/hda2 is the bootable part.
/dev/hda3 is my shared space
/dev/hda5 is swap
/dev/hda6 is /
/dev/hda7 is /home
/dev/hda8 is another linus partition.. i done remember what is it used for..
lilo was installed on the MBR, i tried re-running the boot setup from linux, but it failed.
/dev/hda2 is the bootable part.
/dev/hda3 is my shared space
/dev/hda5 is swap
/dev/hda6 is /
/dev/hda7 is /home
/dev/hda8 is another linus partition.. i done remember what is it used for..
lilo was installed on the MBR, i tried re-running the boot setup from linux, but it failed.
•
•
•
•
Originally Posted by techhelpforme
/dev/hda2 is the bootable part.
•
•
•
•
Originally Posted by techhelpforme
/dev/hda8 is another linus partition.. i done remember what is it used for.. i tried re-running the boot setup from linux, but it failed.
I don't mean to sound short or anything like that, but given the fact that you've got a dual boot/dual OS system, and there seem to be problems with both OSes, you'll need to provide us with as much exact and specific information as possible in order for us to help you resolve the problems most quickly.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
hey... thnx for ur help
when I tried to fix LILO from my SUSE installation CD, I got the following msg from YaST
The partitioning on your disk /dev/hda is not readable by the partitioning tool "oarted" that YaST uses to change the partition table.
when I get this, I cant play around with my partition. I tried to re-install LILO and this is the msg I get.
WARNING: LBA32 addressing assumed
Added SUSE_LINUX_9.3 *
Added Windows
Added Failsafe_--_SUS
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
any suggestions?
when I tried to fix LILO from my SUSE installation CD, I got the following msg from YaST
The partitioning on your disk /dev/hda is not readable by the partitioning tool "oarted" that YaST uses to change the partition table.
when I get this, I cant play around with my partition. I tried to re-install LILO and this is the msg I get.
WARNING: LBA32 addressing assumed
Added SUSE_LINUX_9.3 *
Added Windows
Added Failsafe_--_SUS
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
Warning: LBA32 addressing assumed
Fatal: Cant put the boot sector on logical partition 0*0306
any suggestions?
•
•
•
•
Originally Posted by techhelpforme
any suggestions?
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
1. The "parted" partitioning tool can be a bit tempermental if you've used some other partitioning utility to create/manipulate your partitions. If you actually need to change the partitions, you might have to try another tool.
2. Lilo can reside either in the MBR of a drive, or in the boot sector of a partition on that drive. If you install it on a partition or as opposed to the MBR, that partition must be a Primary partition, not a Logical partition. In other words, it sounds like you just specified the wrong location when you tried to reinstall Lilo.
If your lilo.conf file contains the line:
Boot=/dev/hda
you should be able to boot into rescue mode from the SuSE CD and then issue the following 2 commands to reinstall Lilo to the MBR:
chroot /mnt/sysimage
/sbin/lilo
2. Lilo can reside either in the MBR of a drive, or in the boot sector of a partition on that drive. If you install it on a partition or as opposed to the MBR, that partition must be a Primary partition, not a Logical partition. In other words, it sounds like you just specified the wrong location when you tried to reinstall Lilo.
If your lilo.conf file contains the line:
Boot=/dev/hda
you should be able to boot into rescue mode from the SuSE CD and then issue the following 2 commands to reinstall Lilo to the MBR:
chroot /mnt/sysimage
/sbin/lilo
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
![]() |
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: help me, please!
- Next Thread: For maggiebr: HijackThis log
Views: 4491 | Replies: 28
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
acrobat adobe adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime ddos domains e-mafia education email europe exam exploit fake fancheckvirus gaming gumblar halloween herss.exe hijack hosting internet kaspersky legal mail malware mcafee mega-d messagelabs microsoft mobile nazi news obama onlinethreats paedophile parents patch pc phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect reliability report research risk rogueantivirus rootkit samhain sans school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec threat trojan unwanted update usa virus viruses vista volume war warning windows worm yahoo zero-day zeroday






