Confused with Combofix and Vista

Discussion in 'Malware Help (A Specialist Will Reply)' started by SLoTH_XVX, Oct 10, 2008.

  1. SLoTH_XVX

    SLoTH_XVX Private First Class

    I have gone step by step on the READ & RUN ME FIRST and have had no troubles until I got to the Combofix and am lost.

    I read thru the instructions several times and do not see (in the linked instructions from 'How to use ComboFix') on how to get the Combofix to 'work'.

    I have preformed the complete READ & RUN ME FIRST without any issues on XP (on a different PC) but now am L O S T with Vista and getting the ComboFix to run. I click the icon and it starts but never goes beyond the initial green bar.

    I read thru the 'Vista Recovery Enviroment' link on the 'How to use ComboFix' page and am so mixed up that I am totaly stuck.

    Any help or direction on this would be appreciated.

    Thanks in advance, SLoTH_XVX:confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you disable UAC as requested in the READ & RUN ME instructions? Did you reboot after disabling? Also have you shut down your antivirus and other protection programs?
     
  3. SLoTH_XVX

    SLoTH_XVX Private First Class

    Yep...yes...and yes.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then skip it and run MGtools!

    Also tell us why you are running the READ & RUN ME.
     
  5. SLoTH_XVX

    SLoTH_XVX Private First Class

    Skipped it....

    I originally began the 'R&RM' because of a notification of a 'iFRAME.JP' Trojan/Virus. The virus 'blocker' stated it was quarentined but I hadn't 'cleaned' this machine since it was purchased and it is a laptop my wife uses....she's not as careful as I am on it. So I thought it seem to be running (considerably) slower than when we purchased it and I got excelent results when I used the 'R&RM' for the PC with XP on it several months ago....

    All of the Scans were clean except the MaylwareBites scan it found one issue (registry data item: hijack.StartMenu)and resolved it.

    We do have 'Webroot Spy Sweeper that was included with the laptop when we purchased it and it now keeps showing alerts or notifications "The Internet Communication sheild has blocked access to: (then it lists sites being blocked, one at a time). I assume this is a good thing and happening because one of the steps in the 'R&RM' cleaned out a file that previously stored the names of these sites correct? The notifications come up every 10-20 seconds.....

    I will post the logs shortly.
     
  6. SLoTH_XVX

    SLoTH_XVX Private First Class

    These were the only two log I got....the others had nothing to log?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly do you have installed from WebRoot? Is it just the antispyware program or does it have other components?

    You will have to be much much more specific as I have no idea what you are referring to. Your logs are all clean other than the below minor details. Are you actually having any current malware problems? If yes, be specific on what they are.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - MRI_DISABLED - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

    After clicking Fix, exit HJT.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Users\McBriarty\AppData\Local\Temp\
     
  8. SLoTH_XVX

    SLoTH_XVX Private First Class

    chaslang, I'm sorry I was not more specific, when I get home I will confirm what part of WebRoot is installed. (sorry I haven't reponded sooner...busy weekend)

    As far as I know WebRoot is just the anitspyware, it was installed when we purchsed the lap top, but I will check when I get home later tonight.

    As for current malware issues, not that I know of. I will run the suggested steps and get back to you tonight.

    Thank you for your assistance this far.
     
  9. SLoTH_XVX

    SLoTH_XVX Private First Class

    chaslang, again thank you for your help.

    I have run C:\MGtools\analyse.exe and removed the specified files.

    The WebRoot is only an anti-spyware program. The 'alerts' have stopped and the laptop seems to be working very well. I have not noticed any other issues.

    My original post was only to find out about the ComboFix. The instructions posted here at MajorGeeks are AWESOME...however, once I followed the instructional link for the ComboFix the instructions seemed rather incomplete for Vista Users (bleepingcomputers.com).

    As in the past MajorGeeks have been most helpful with my issues, Thank you.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know all about it. We had our own procedures here for ComboFix at one time but the author wants us to link to that page as the official procedure.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds