Quick Combofix question

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vallander, Jan 1, 2010.

Thread Status:
Not open for further replies.
  1. Vallander

    Vallander Private E-2

    Hi,
    First, THANK YOU for your READ ME FIRST procedures and your willingness to help! My computer was showing vundo.h and Trojan.Agent/Gen Nullo[short] before the procedures and is now coming up clean. I am now able to access Safe Mode once again, and when I select it I am given a choice to enter the recovery console or XP Pro. However, in the combofix instructions, it said that once the Recovery Console was successfully installed, "On each restart of the machine, a black screen will offer you the option to boot into recovery console mode. For normal use, just ignore the black screen. Windows shall boot normally in 2 seconds." I do get a black screen, but there isn't anything written on it! The computer proceeds to boot normally. Should there be a screen that offers just the Recovery console that I can't see? Is there a command to select it? The viruses that I had prevented me from accessing both before, even off my XP disk. Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you properly installed the Recovery Console, there should be a screen that appears giving you the choice of booting it or booting into Windows. Unless you attach all of the logs from the cleaning process, we have no idea what your status is or whether the Recovery Console shows as being installed.

    Are you saying you see the option only when you have elected to boot your PC in safe boot mode but not when you allow it to boot in normal mode? This would make no sense since chosing the Recovery Console means you are not booting Windows at all and it does not care about safe boot or normal boot mode.

    See the black screen snapshot half way down the page in the below link. This is what you should see at bootup if you do not press any keys:

    http://www.bleepingcomputer.com/tutorials/tutorial117.html
     
    Last edited: Jan 3, 2010
  3. Vallander

    Vallander Private E-2

    Well, I followed your directions, installing the recovery console when using combofix. I did it exactly as directed. Combofix gave the exact message that "the recovery console had been successfully installed' that appeared in the directions. Combofix ran successfully and eradicated the virus. BUT --when I start up the computer now, the screen that you directed me to in your last post does NOT appear when the computer boots --it simply goes from dark, blank screens to XP. If I hit F8 to go into safe mode, I get a screen with a number of choices, with safe mode on top. If I select safe mode here -THEN I get the screen. It is exactly the one you just posted as an example, with a choice between the Recovery Console and Windows XP professional. It doesn't make sense to me either, but that's what happens. I have attached the combofix log. It is worth noting that the virus in question prevented me from booting into safe mode AND prevented me from booting to the recovery console even off teh XP disk.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As requested in my last message, I need all of the logs from the READ & RUN ME cleaning procedure.
     
  5. Vallander

    Vallander Private E-2

    Okay, they are attached. The SAS and AntiMalwareBytes logs are from before combofix was used. Afterward, they showed zero infections. The rootkit log also showed zero as it was run after combofix as well.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 16



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    As far as you issue with the Recovery Console not showing, everything looks fine. The only guess I have is that you are missing it. Try the below. Run MSconfig and select the boot.ini tab. You should see an image like below:

    http://forums.majorgeeks.com/chaslang/images/msconfig-bootini.jpg

    However you will notice that in the box for Timeout: you are currently set to 2 seconds. Try changing it 15 and click Apply. This is just as a test. You can change it back to what you prefer later.. This should cause a noticebly longer delay in the boot window that allows you to choose between booting to the RC or to your normal Windows partition. Reboot after making the change and see if you now see an option for selecting the RC
     
  7. Vallander

    Vallander Private E-2

    Sorry, I was out of town for a bit there. My son checked in with this but didn't do any of it. I followed all your instructions. The logs are attached and everything seems to be fine. Am I cured?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  9. Vallander

    Vallander Private E-2

    No, no more problems. I will follow these directions for the follow-up.
    THANK YOU SO MUCH! I feel rescued! You and this site are absolutely awesome! Thank you!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds