Combofix Compromised Alert Message

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bper, Jun 15, 2009.

  1. bper

    bper Corporal

    Hello,

    HP zv5220us laptop running xp service pack 2.

    Normal mode does not display desktop or icons, blank black screen only.

    Safe mode boots up fine. I try to do as much as I can with read me first, but can't get far.

    Combofix gives message:

    !! ALERT !! It is NOT SAFE to continue!

    The contents of the ComboFix package have been compromised.
    Please download a fresh copy from bleeping computer.

    Note: You may have been infected with a file patching virus (Virut)

    How should I proceed?

    Thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to bring you the bad news but if ComboFIx is detecting Virut, your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  3. bper

    bper Corporal

    While searching the net for possible causes/solutions, all indications seemed to point to a reformat/re-install. I was prepared to do this, but wanted to get your insight, Chaslang, before I proceeded.

    Thanks again for your response and assistance, as always.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    Chiming in here. According to navyjax2 he has had luck with
    Nortons W32.Virut Removal Tool

    http://www.symantec.com/security_response/writeup.jsp?docid=2009-022016-4444-99

    He also used a combination of Microsoft’s Malicious Software Removal Tool.
    http://majorgeeks.com/Microsoft_Malicious_Software_Removal_Tool_d4471.html

    And Spybot.
    http://majorgeeks.com/Microsoft_Malicious_Software_Removal_Tool_d4471.html

    Spybot will not run in normal mode with this infection. To get spybot to run, navigate to the spybot install folder. Generally c:/program files/spybot look for 2 files with 10 random letters ending in .SCR. One is for updates and if you double click it, will do nothing. The other one will run spybot.

    Worth trying before a format.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many AV companies have tools that attempt to remove Virut but they simply don't always work and frequently can even render a PC unbootable.

    The newer forms of Virut that are around do not seem to get fixed by any removal tools and in many cases, the scanners do not even detect the infection at all. There are actually bugs in the malware code itself which has cause it to become harder to properly detect and remove. And even if you think you have gotten all traces removed, these infections normally leave PCs in a very unreliable/untrustworthy state.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds