Combofix won't work

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vroom, Nov 11, 2008.

  1. Vroom

    Vroom Private E-2

    I have proceeded down through all of the instructions for removal of malware to Combo.fix which will not run. It says it is detecting rootkit and closes down and reboots my computer. What's next?

    I am attaching the logs that I have created so far.

    Also, since running SuperAntiSpyware and Spybot S&D I no longer have any Audio and I have a PCI device that will not work. Can you help with these problem?

    Please help!!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still need the MGLogs.zip from running the MGTools.exe.
     
  3. Vroom

    Vroom Private E-2

    Hello TimW

    I have attach the MGlogs.zip file as requested. I did not proceed to MGtools after finding that Combofix would not work and I have not gone back to try and run Combofix again.

    I am still without any audio and I still have the PCI device error message requesting new hardware added and the wizard come up when I reboot.

    Thanks for your help
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Turn off all your anti-virus software and anti-spyware and then try running combo again.

    Also use windows explorer to find and delete:
    C:\Documents and Settings\Bryson\Application Data\vghd

    Did you have any hardware attached that you no longer have...possibly a usb device?

    I see you have a registry program....and you say that the sound drivers were removed after running Spybot...perhaps you should reinstall what spybot removed on that last run.
     
  5. Vroom

    Vroom Private E-2

    1. I'm not sure how to turn off all the anti spyware I now have on my PC, but I made sure that nothing was open on my machine. Then I disabled Norton Antivirus Auto-Protect and ran Combofix. It ran successfully and wrote the log Combofix.txt to my C:/ drive.

    2. Using Windows Explorer I deleted the file: C:\Documents and Settings\Bryson\Application Data\vghd

    3. I have these other hardware devices that are not currently connected to my PC.
     
  6. Vroom

    Vroom Private E-2

    I hit the "Edit" button by mistake so it cut my reply off.

    Continued here:

    2 GPS receivers
    1 camera
    1 Game controller/Joystick (used for Flight Simulator)

    I also have a USB hub connect to one USB port so that I can run multiple devices without have to crawl behind the unit to plub them in.

    4. The registry program is PC Tools Registry Mechanic which is what I thought I was supposed to install when READ & RUN ME FIRST called for downloading and running CCleaner. It was the recommeded download on that instruction page so that is what I did. It was my first foray into your website and I was confused so if I did the wrong thing you need to let me know. I have not run CCleaner only Registry Mechanic. Please be specific about which link I should use if I need to go back there. By the way, Registry Mechanic pops up everytime I reboot and says that there are registry errors that I need to repair, which I do, and they continue to pop up on the next reboot.

    I don't know exactly when I lost the Audio, I just know that it wasn't there at some point after starting to work on READ & RUN ME FIRST. If I need to go back and reinstall something that one of the Malware programs deleted would you please give me specific instructions. I am not sure that I would know where to go and what to look for.

    Hope this helps, I as sure grateful for YOUR help,
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Any one of those items could be responsible for the device error message.

    Please open Registry Mechanic ( which was a sponsored ad on the page for CCleaner, not one of the four links ) ..click the Restore button...On the Restore registry backup screen, select the check box next to the appropriate registry backup in the list. ( I want you to restore all of them! )

    Click the Restore button. Changes implemented in the repair event which created the selected backup are reverted back to their original state, and you are returned to the main page.

    Now If that was successful, go to add/remove programs and uninstall it --> but only if the restore option worked.

    Please attach that log and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  8. Vroom

    Vroom Private E-2

    Registry Mechanic has been deleted by using Add/Remove Programs.

    I re-ran the C:\MGtools\GetLogs.bat file and the two requested files are attached here.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. If restoring the registry items did you help with your audio, then I suggest you post in the software section as they can guide you to download the appropriate drivers.

    I would suggest you use CCleaner in the future to clean your leftover registry items.

    Let's just clean up from all the scans:

     
  10. Vroom

    Vroom Private E-2

    Thanks a lot Tim, I think my machine is clean now and I have worked through the protection item. I really appreciate your help.

    Now I am moving on to the software forum as you suggested to see if I can solve my audio problem.

    Again, many thanks!!!!!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome....and good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds