ComboFix and Windows Recovery Console Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by markedbyone, Dec 1, 2008.

  1. markedbyone

    markedbyone Private E-2

    My computer is running very slowly, so I tried to go through the steps recommended to speed it up before posting here, but I ran into a problem. I downloaded the Microsoft Service Pac, (#2, for XP), and then followed the instructions to allow ComboFix to boot it up. I placed the icon over combofix, bit instead of doing what the instructions said it would, I got an error message, saying "Boot Partition cannot be enumerated correctly." What does this mean? I tried to run the service pac w/o combofix, and it just shuts itself off. Should I run Combofix anyway? Any help would be so appreciated. Thanks, Mark
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just skip that step and do the rest of the instructions. When you are done, please attach the logs for:
    MBAM
    SAS
    Combo
    MGTools.exe ---> C:\MGLogs.zip
     
  3. markedbyone

    markedbyone Private E-2

    Thanks so much for your help, TimW. I ran comboFix and here are the first three logs.
     

    Attached Files:

  4. markedbyone

    markedbyone Private E-2

    Here's the last one. Thanks again!!!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At the moment I can not open your Combo log.....not sure if it is a site error or not.

    You need more ram:
    Code:
    Total Physical Memory    512.00 MB    
    Available Physical Memory    83.84 MB
    
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now tell me exactly what malware issues you are having.

    Bear in mind that trying to install the recovery console with Combo sometimes does not work.
     
  6. markedbyone

    markedbyone Private E-2

    TimW, I ran the ATF as you said and deleted all. A friend helped me set up my computer a while back, and said I didn't need any virus or spyware protection, so I have been running my computer for about a year and half without any protection. A few months back i must have picked something up, and it began running slower and slower, until it took like 10 minutes to boot up, and programs would hardly run. I started trying to fix the problems a couple of weeks ago, as I run my business with my computer and I'm on it a lot. I have got rid of a lot of trojans and whatnot, but it hasn't began running like it used to. I realize I probably should expand my ram, but I haven't done it yet, as it was running fast enough until recently. After reading your site, I realize I need to have it protected as well. I purchased the computer used, and so don't have all the cd's with it. I was going to just wipe it and start over, but the partition in it seems to be corrupted, so I need to fix the problems, not start over. Should I run combofix again and try to put the txt back up, or upload it again? Thanks, Mark
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can't believe you ran for so long without protection and can still operate your system. :confused

    I finally opened the combo log......and a question:
    Did you install this:
    c:\program files\KeyScrambler
    c:\windows\system32\drivers\keyscrambler.sys
     
  8. markedbyone

    markedbyone Private E-2

    Yeah, I installed it because it was recommended in this site to stop key loggers, and since I ran another scan and found one, I thought I'd try to stop it for now.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are you running? Are you still having malware issues? Did you install and AV program?
     
  10. markedbyone

    markedbyone Private E-2

    Tim, thanks again for your help, I am running, although slower than I used to. I am installing an AV now, so hopefully it won't get that bad again. you guys rock on MG!! mark
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your available ram is seriously low, so I would suggest more ram. Some of your programs are what is slowing you down. You may wish to post in the software forum in regard to stopping some of your startup programs ( CCleaner will list these).

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. markedbyone

    markedbyone Private E-2

    Tim, I tried to unistall combofix as you said, and although I saved it on my desktop, it says it is not there. The combofix.exe icon is on the desktop, but is it possible I screwed up where I saved it? Any help would be appreciated.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just right click the icon and delete it as well as C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds