Combofix reboots...then nothing

Discussion in 'Malware Help (A Specialist Will Reply)' started by alchemilla, Nov 3, 2008.

  1. alchemilla

    alchemilla Private E-2

    Hello -- was going through READ AND RUN ME and found I had Virtumonde. I was ready to start Combofix. Upon double clicking the icon, a message came up saying Combofix had detected rootkit activity and would need to reboot. After rebooting, a DOS type window briefly flickered that said "GREP is not recognised as an external file blah blah@, too quick to read it all, then nothing...

    I know I am not supposed to click on things during Combofix, BUT in order to reboot, I have to first end a mysterious program called sprtcmd.exe in order to reboot. Then after rebooting, all my start up applications opened, which I had to click on to close.

    If I then double click on Combofix again, thinking I should try again, I again get the message that it needs to reboot.

    What should I do to get this to run successfully?

    Thanks for your help, dear fellow Geekolas.

    --alchemilla
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try running it in safe mode. You could also try renaming it as suggested in the instructions. If you still have a problem, run the other scans first and then see if you can run Combo. :)
     
  3. alchemilla

    alchemilla Private E-2

    Thanks. I think McAfee was interfering with the proper download of Combofix in the first place. I turned off McAfee even when downloading and that may have solved the issue. I renamed Combofix also, and it ran successfully. I did combofix last, after MG tools.

    I am attaching the logs, all created today. You should note that I ran the SAS, Spybot and MBAM two days ago as well (that's when I got stuck at Combofix) and that is when I saw Virtumonde mentioned, in MBAM. My results looked different today.

    Today's logs:
     

    Attached Files:

  4. alchemilla

    alchemilla Private E-2

    And the other logs:

    Thanks for this -- your forums are packed with malware sufferers, even more so than the last time I had a problem. I hope you guys get some sleep occasionally!

    alchemilla
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would appear that the scans took care of the malware.....if you are not having any other issues, we can do our final clean up:

     
  6. alchemilla

    alchemilla Private E-2

    Tim
    Well, things SEEMED better...but McAfee has picked up and quarantined four times today a something called Tool-NirCmd. Could that possibly just be a bit of Combofix?

    Here's hoping,
    alchemilla
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do the final cleaning? And yes....a false positive.
     
  8. alchemilla

    alchemilla Private E-2

    Nope, will do it now. I wanted to make sure I didn't need to do the whole Read and RunMe process again first.

    THank you Tim, you're a dear!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome......safe surfing, :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds