Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: rassel on January 08, 2008, 09:55:28 AM

Title: Is combofix safe to use now?
Post by: rassel on January 08, 2008, 09:55:28 AM
 ??? is combofix safe to use now i have downloaded but after downloaded i saw some web page that the combofix has roodkits or i dunno whats that  :P ? can any one tell me is the combofix safe to use now?
Title: Re: Is combofix safe to use now?
Post by: Lisandro on January 08, 2008, 01:19:34 PM
If you download from the official site, it's a security/cleaner tool. It's safe, although it could be for advanced users (not simple).

Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.

Double click combofix.exe and follow the prompts.

When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall.
Title: Re: Is combofix safe to use now?
Post by: rassel on January 09, 2008, 11:09:35 AM
 :D Wow after i finish running the combofix it safe a lot of space in my computer and increase 30% faster than before!!!! :o
Title: Re: Is combofix safe to use now?
Post by: Lisandro on January 09, 2008, 12:56:04 PM
:D Wow after i finish running the combofix it safe a lot of space in my computer and increase 30% faster than before!!!! :o
But the most important is to post the logs here and get clean, otherwise, the viruses will come back.
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 09, 2008, 10:40:19 PM
The definitive guide for combofix can be found here http://www.bleepingcomputer.com/combofix/how-to-use-combofix  And it is the only official guide
Title: Re: Is combofix safe to use now?
Post by: rassel on January 10, 2008, 05:56:33 AM
Tech you ask me to post the logs here but i cant find it i close it already so how to get it back ???
Title: Re: Is combofix safe to use now?
Post by: oldman on January 10, 2008, 06:05:55 AM
Look in c:\combofix
Title: Re: Is combofix safe to use now?
Post by: rassel on January 11, 2008, 09:52:24 AM
Ok here is the post




Title: Re: Is combofix safe to use now?
Post by: essexboy on January 11, 2008, 12:42:06 PM
Please Download NoLop[/color] to your desktop from one of the links below...
Link 1 (http://www.spywareedge.net/nolop/NoLop.exe)
Link 2 (http://www.spywaretimes.com/Tools/download/21/chk,ed0778d88843ca2625ab6208a197bcc5/)
Link 3 (http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item16) --If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx (http://www.boletrice.com/downloads/mscomctl.ocx) to your system32 folder then rerun the program. --
Title: Re: Is combofix safe to use now?
Post by: rassel on January 12, 2008, 05:22:07 AM
Is this program safe to use  :o? Will it delete some of the files that i need ? Im afraid that it will deleted some of my computer program that i need to use ;D
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 12, 2008, 11:41:15 AM
No you have a LOP infection that needs to be removed.  The programme is safe 
Title: Re: Is combofix safe to use now?
Post by: rassel on January 13, 2008, 10:15:42 AM
Well ok i trust you i will try to use it now
Title: Re: Is combofix safe to use now?
Post by: rassel on January 13, 2008, 10:57:10 AM
Erm essexboy i wanna say that i dont really know what the mean of (Please Post the contents of C:\NoLop.log along with a fresh HijackThis log) please give some idea
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 13, 2008, 01:43:17 PM
OK nolop will generate a log at this location C:\NoLop.log

Download & Run HijackThis.exe

Don't use the Analyse This button, its findings are dangerous if misinterpreted.
Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.


Title: Re: Is combofix safe to use now?
Post by: rassel on January 14, 2008, 11:07:10 AM
Hey i cant post it. It is too long for me to post here it says that not more than 100000 word. So how can i do make a Additional Options? or what?
Title: Re: Is combofix safe to use now?
Post by: Darth.Mikey on January 14, 2008, 11:22:23 AM
You can save the log into a .txt file and attach it to your next post, under additional options click attach select browse and select your log file.

Or you can split the log into multiple posts.
Title: Re: Is combofix safe to use now?
Post by: rassel on January 15, 2008, 09:47:01 AM
Sry i cant post the log on here so i did this an this the log you want.....
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 15, 2008, 09:05:48 PM
Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
O4 - HKCU\..\Run: [waitdead] C:\DOCUME~1\ADMINI~1\APPLIC~1\GREATO~1\Joybeep.exe
O4 - HKLM\..\Run: [eggs joy math type] C:\Documents and Settings\All Users\Application Data\Bind army eggs joy\two plan.exe
O8 - Extra context menu item: ·¢ËÍͼƬµ½ÊÖ»ú - C:\Program Files\P4P\cx.htm


Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis.

1. Please open Notepad2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
Folder::
C:\Documents and Settings\All Users\Application Data\Bind Army Eggs Jo
C:\Documents and Settings\Administrator\Application Data\Greatonline


3. Save the above as all files CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.

(http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif)


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
Title: Re: Is combofix safe to use now?
Post by: rassel on January 16, 2008, 10:21:52 AM
OK thanks and here is the post but im not sure weather i did it correctly or not. ;D
Oh ya and you said that about CFScript.txt is from where i have no idea so what i did is go to the folder that you give me (C:\Documents and Settings\All Users\Application Data\Bind Army Eggs Jo) and (C:\Documents and Settings\Administrator\Application Data\Greatonline) and i extract the files into the notepad.txt. Is that correct?
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 17, 2008, 08:22:13 PM
No what you needed to do was copy the text in the quote box to a notepad file and then save it as cfscript, then drag and drop that on the combofix icon

Then it would have deleted these two folders and any associated files

C:\Documents and Settings\All Users\Application Data\Bind army eggs joy
C:\Documents and Settings\Administrator\Application Data\GreatOnline


They are both LOP folders which are not good

Also you do not appear to have removed these lines from Hijackthis

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
O4 - HKCU\..\Run: [waitdead] C:\DOCUME~1\ADMINI~1\APPLIC~1\GREATO~1\Joybeep.exe
O4 - HKLM\..\Run: [eggs joy math type] C:\Documents and Settings\All Users\Application Data\Bind army eggs joy\Type Scr.exe
O8 - Extra context menu item: ·¢ËÍͼƬµ½ÊÖ»ú - C:\Program Files\P4P\cx.htm
O8 - Extra context menu item: ʹÓÃËѹ·Ö±Í¨³µÏÂÔØ - C:\Program Files\P4P\dl.htm


Until you remove them you are still infected

Title: Re: Is combofix safe to use now?
Post by: rassel on January 18, 2008, 10:06:46 AM
Ok  ;) im very thanks for your help to my laptop and here is the newest post you want it and if anything wrong tell me. :P and i have follow what you have said
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 18, 2008, 08:31:47 PM
Can you manually delete these two folders

C:\Documents and Settings\All Users\Application Data\Bind army eggs joy
C:\Documents and Settings\Administrator\Application Data\GreatOnline

Once they are gone you look to be clean
Title: Re: Is combofix safe to use now?
Post by: rassel on January 19, 2008, 06:06:20 AM
Wow thats really dangerous when i open this file C:\Documents and Settings\Administrator\Application Data\GreatOnline avast suddenly pop up and said that there is trojan. Thanks a lot essexboy and i cant delete this folder C:\Documents and Settings\All Users\Application Data\Bind army eggs joy and it says that
it is begin use by another person or other program so how can i delete it?
Title: Re: Is combofix safe to use now?
Post by: oldman on January 19, 2008, 06:23:57 AM
rassel

Please boot to safe mode and try to delete it from there. Remember to empty the recycle bin when you are done.
Title: Re: Is combofix safe to use now?
Post by: rassel on January 21, 2008, 09:35:32 AM
ok thanks a lot from you all :) and i there is another problem which is i deleted this folder (C:\Documents and Settings\Administrator\Application Data\GreatOnline) and its not over there and after the next day i go check and the folder is over there so i deleted it again and today is appear at (C:\Documents and Settings\Administrator\Application Data )this folder again. How to avoid it from my laptop ???

Title: Re: Is combofix safe to use now?
Post by: essexboy on January 21, 2008, 11:13:57 PM
Rerun combofix again and I will have a look see
Title: Re: Is combofix safe to use now?
Post by: rassel on January 23, 2008, 05:40:59 AM
Ok and sry for the late reply  :P  :D
And do u need hijackthis log ? If u want than tell me.
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 23, 2008, 10:15:42 PM
LOP is still there if this does not work I will have to use a different hammer

Please download the OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe).
Code: [Select]
C:\WINDOWS\Tasks\AED442E7918FFD47.job

Title: Re: Is combofix safe to use now?
Post by: rassel on January 24, 2008, 10:01:47 AM
This is the post 8)


C:\WINDOWS\Tasks\AED442E7918FFD47.job moved successfully.
[Custom Input]
< C:\DOCUME~1\ADMINI~1\APPLIC~1\GREATO~1 >
File/Folder C:\DOCUME~1\ADMINI~1\APPLIC~1\GREATO~1 not found.
< c:\docume~1\admini~1\applic~1\greato~1\heck peak bone.exe >
File/Folder c:\docume~1\admini~1\applic~1\greato~1\heck peak bone.exe not found.
 
OTMoveIt2 v1.0.14 log created on 01242008_165934
Title: Re: Is combofix safe to use now?
Post by: rassel on January 24, 2008, 10:03:25 AM
OH ya i forget to tell u that the greatonline have been removed from my computer and not in there anymore

Thanks essexboy
Title: Re: Is combofix safe to use now?
Post by: essexboy on January 24, 2008, 09:39:25 PM
Ok and then LOP is gone - trry not to get another one  ;D
Title: Re: Is combofix safe to use now?
Post by: rassel on January 25, 2008, 09:11:51 AM
He he ok thanks for your help ! ::) ;D