PDA

View Full Version : BSOD after removing hlp.dat



kidzrback
2011-01-09, 19:50
Hi all,

I recently ran a scan and found one error. I fixed the problem and now have the dreaded blue screen of death on both normal and safe modes on XP Home.

I have been able to navigage to the SnD logs and recovery files and found what I think needs to be restored.
Documents and Settings/All Users/Documents/Servers/hlp.dat
was what was removed.

Problem is, I can't run any .exe files from the windows repair screen.
I've also been able at least to copy the zip file that contained the hlp.dat file, but when I go to extract it, there is a password. I thought I could try to manually put it back.

I know this may be malware but I would like to get my computer back to where it was and then take care of it.

Also, I have scanned my disk for any copies of hlp.dat and there are none.

Any help much appreciated.

Zenobia
2011-01-10, 06:12
The password is recovery.
However,I suggest you go to the Malware Removal forum section and ask the advice of a helper,instead of just recovering the file and going from there.Perhaps there is some way to get into Windows without having to recover that particular file.Or,if you have to restore it,at least there is someone right there to help you afterwards.
You can't run the scans,etc. required,obviously,but you can go in there and explain the situation,and ask for help.

Malware Removal:
http://forums.spybot.info/forumdisplay.php?f=22

kidzrback
2011-01-10, 14:46
Thanks Zenobia,

That worked great. Now at least I am back to a working computer. I will check out the other forums should I need further assistance.

Zenobia
2011-01-10, 22:19
You're welcome. :)
As for Documents and Settings/All Users/Documents/Servers/hlp.dat,please see:
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Virus%3AWin32%2FBamital.H
And also:
http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentpqu.html
From everything I found,it doesn't look like a legit file,so please do go to malware removal if you need help.