combofix question

Discussion in 'Malware Help (A Specialist Will Reply)' started by opal219, Apr 14, 2008.

  1. opal219

    opal219 Private First Class

    I'm doing a complete system malware clean .. following the instructions in the removal process. Quick question
    How long should the screen that says "preparing to run" take to initialize?
    I let it sit over an hour and it was still preparing to run.

    btw.. I'm finding this cleaning process, informative, easy (mostly) and almost entertaining
    thanks for being here!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What utility is "preparing to run"? Stop it and move on ....:) right...combofix...skip it and continue with the instructions.
     
  3. opal219

    opal219 Private First Class

    the preparing to run message is the first combofix screen that comes up. There doesn't seem to be a way to skip it. The instructions said not to click anywhere in the command prompt screen while combofix is running.

    I am fairly sure that I removed the biggest problem malware back in the first couple of steps (got a program out called adzgalore) I was getting audio "commercials" when I wasn't doing anything on the net... and pop ups that just happened when I didn't have a browser open. That seems to have stopped.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need the logs from running MalwareBytes, SASpyware and esp. the MGLogs.zip from running the MGTools.exe. :)
     
  5. opal219

    opal219 Private First Class

  6. opal219

    opal219 Private First Class

    ::smacks head:::
    you meant skip combofix, right?

    off to run MGTools.... back with logs in a bit
     
  7. opal219

    opal219 Private First Class

    I tried to just edit the last post to add the MGTools attachment.. didn't find an edit command.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like the scans took care of most of it ...let's just do this:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Marilyn\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  9. opal219

    opal219 Private First Class

    ok.. printing instructions.. prior to disabling the AV software et al, should I be disconnecting from the internet? (I'm beind a wireless router)
     
  10. opal219

    opal219 Private First Class

    ok.. finished with thoes instructions...
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...the only thing you have that is open to debate is the" ixquick Toolbar - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this."

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  12. opal219

    opal219 Private First Class

    ty ty ty!
    I wasn't able to get combofix to work.. that preparing to run message lingered for over an hour.. so we just skipped that.

    Ixquick says it doesn't play the spyware game.. that's pretty much why I use it instead of google or ask.. or yahoo search, and I like the interface.

    ok.. off to follow removal instructions then clean up the restore points

    thanks again! yall are the best!
     
  13. opal219

    opal219 Private First Class

    just a finishing up question.. all thoes fun apps now on my desktop (not the shortcuts.. but the .exe files) Can they be moved to another folder to clear up the real estate on my screen? Shared folder maybe?
    I have :
    ashwclnr.exe
    avenger.exe
    mbam-setup.exe
    SUPERantiSpyware.exe
    tfinstall.exe
    and some of their shortcuts...
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...just right click the desktop / new - > folder ...and name it. Then just drag and drop what you want over that folder and drop.
     
  15. opal219

    opal219 Private First Class

    malware all cleaned up

    Sombody asked back in the thread to check back and let yall know how things are running.. good! I'm pretty sure I'm running spyware free now. The system is running a bit slower than it used to with all these apps running to protect the system.. browser comes up slower.. switching apps and multitasking are a bit boggy.
    I have run adaware and got nothing! I tried to run regcleaner.. it crashed on me (first time that's happened)
    quick question - are any of the following programs running all the time redundant?
    threatfire
    superAntiSpyWare
    online armor firewall (for some reason I have two task bar icons for this one)
    comodo BOClean
    avast antivirus

    and with all this stuff, do I need to be running weekly spybot, regcleaner, adaware and hijackthis? I never know when I'm performing overkill.

    thanks
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    YOu can uninstall all of these:
    and You may wish to use a Startup Manager ...

    There is no need to keep HJT ...

    If you right click them ...what appears?

    These kind of questions could be addressed in the software section as far as speeding up your computer and stopping programs from running that may be slowing your system down. :)
     
  17. opal219

    opal219 Private First Class

    thanks TimW
    I'm working on removing thoes.. some are not on the uninstall menu..
    I'll go on over to the software folder in a bit.
     
  18. opal219

    opal219 Private First Class

    right clicking results in identical menus starting with configuration and ending with close GUI interface. I haven't found a merge icons command anywhere.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have been using regcleaner....you may have removed some necc. system files...I hope you made backups. Yes...you should post in software. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds