Can't run computer after running ComboFix

Discussion in 'Malware Help (A Specialist Will Reply)' started by ECR, Nov 3, 2008.

  1. ECR

    ECR Private E-2

    I have a Dell Dimension 4700 running XP Home. It got infected with the Bravix virus that automatically downloads itself as an anti-virus program. I followed the "Read and Run Me First" procedure which resulted in many files being deleted (brastk.exe, Karna.dat, many files with TDSS in the titles, etc.). When I got to ComboFix, it installed and ran OK, but then a screen came up that said that ComboFix needed to reboot, and that I should not try to reboot the machine myself. After reboot, the computer will not load the desktop for any of the four user accounts on the machine. It gets as far as loading the Background picture for each user, but no task bar or icons appear. The icons and task bar do not appear in Safe Mode either.

    I followed the procedure for installing the Windows XP Recovery Console. I can access this, and I read some information on this but its not clear to me how I can use it to help the situation.

    I reviewed a 2004-05 post where a user had a similar problem, and I was wondering if there are now any better fixes available.

    Unfortunately I can't send you logs from the runs of the earlier programs because I can't get to any of my files.

    Any help would be much appreciated.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. ECR

    ECR Private E-2

    I can start up in Safe Mode (Windows XP operating system option) and can log in as any user, but then I just get a black screen with no program icons or taskbar.

    I also tried Safe Mode but selected the "Windows Recovery Console" option, and this gives me a C:/WINDOWS command line but no option to select a user. Can I do anything useful from this command line prompt in the Windows Recovery Console?

    Many thanks for your help!!
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Try to login in normal mode, login to the account you initially ran ComboFix under. Give it a few minutes to load Windows Explorer, if it does not then try the below.

    Press CTRL + ALT + ESC and then look under the Processes Tab. Click on "Image Name" to arrange by name, look for "explorer.exe" and if you do NOT see it then look under the Applications Tab, click on New Task. When the box comes up, type in explorer.exe and hit OK.

    Let me know what happens when you try this.
     
  5. ECR

    ECR Private E-2

    I was able to get icons and the taskbar for all 4 users on this computer by doing the following while logged onto the account where I ran Combofix:

    Hitting Ctrl-Alt-Del and then selecting the "New Task" button under "Applications"

    Typing in "Combofix" and hitting OK

    Combofix seemed to run OK, did not ask for a re-boot, and then the icons and task bar appeared. When I switched users, the icons and taskbar appeared (eventually) for the other users.

    I then ran a couple of virus scans (Avast) that came up OK.

    So at this point it seems things are back to normal.

    Thank you so much for your help. The "Read and Run Me First" procedure was also a huge help.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I would recommend running the scans in the READ ME and attaching the logs so we can confirm you're clean. Just because you are not having any current problems doesn't mean your system is clean. It's up to you but I would recommend it. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds