Help to read combofix log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sh@wn, Aug 5, 2010.

  1. Sh@wn

    Sh@wn Private E-2

    Hello,
    can you help me to read my report of combofix log file?
    I have problem with js/redir virus
    thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach please the rest of the logs from running our malware removal procedure:
    • SUPERantispyware
    • Malware Bytes
    • Root Repeal (If you were able to run it)
    • C:\MGlogs.zip
     
  3. Sh@wn

    Sh@wn Private E-2

    Thank you for your reply.
    I send you the other files.
    Root Repeal.. I don't be able to run it..
    thnaks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing alot to do here, let's run the below and see how your computer behaves afterwards.

    • Did avg alert you to this?
    • What was the exact file path of the threat it was finding? Did it give a path?
    • Are you experiencing any redirects?



    Eseguito da: c:\users\Sh@wn\Downloads\ComboFix.exe <--- You need to move combofix directly onto the desktop as requested before we continue.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    czrhyqly
    wriuaawp
    File::
    c:\users\Sh@wn\AppData\Roaming\hwzypv.dat
    c:\windows\system32\drivers\wriuaawp.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run CCleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and answer any questions I may have asked. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds