Author Topic: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)  (Read 9525 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #15 on: March 05, 2011, 12:24:27 PM »
It was actually TDL4 in the MBR - did Avast alert you to this ? - Ahh no I see you are using V5 and not V6

Go to Control Panel and select Internet Options
Select the Connections TAB
Select LAN settings button
Ensure there is no tick in the Proxy Server box
Select OK and restart Internet explorer


And for Firefox there are instructions on this page and you want the setting to be no proxy

Whitesmoke can be a right pig to get rid of despite the authors claims that it is a good programme

Dorian Saignren

  • Guest
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #16 on: March 06, 2011, 12:48:33 AM »
Alright, definitely no proxy.  And I updated Avast's program and double-checked the database actually just after I successfully ran ComboFix.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #17 on: March 06, 2011, 01:18:41 PM »
What problems are you experiencing now ?

Dorian Saignren

  • Guest
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #18 on: March 07, 2011, 02:13:08 AM »
Nothing seems to be having any issues, though Avast has been notifying me about potentially dangerous programs starting up, I normally cancel them...

Is there a way to check and record all running processes, including their file paths and preferably usage?  If so, that is something I'd like to be able to do regularly so I can double check everything, might help in finding fake processes lol...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #19 on: March 07, 2011, 12:18:01 PM »
There are two ways of doing that using either process explorer from Sysinternals or running OTL and looking at the processes
Quote
========== Processes (SafeList) ==========
 
PRC - [2011/03/03 16:37:59 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner.DORISAI1\Desktop\OTL.exe
PRC - [2011/01/13 03:47:34 | 003,396,624 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/01/13 03:47:33 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/06/12 22:45:46 | 000,172,032 | ---- | M] (New Boundary Technologies, Inc.) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 10:01:16 | 000,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\Philips\SPC610NC\Monitor.exe
PRC - [2006/05/23 21:22:36 | 000,573,440 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2006/01/02 19:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/12/27 12:20:14 | 000,413,696 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2004/11/05 09:47:00 | 000,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/03/03 16:37:59 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner.DORISAI1\Desktop\OTL.exe
MOD - [2011/01/13 03:47:35 | 000,189,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/11/05 09:47:00 | 000,069,722 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
 

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

 Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Quote
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS] 
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Click Start > Run  and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself.  MBAM can be uninstalled via control panel add/remove along with ERUNT.  But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

   Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 24.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u24-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u24-windows-i586-p.exe and select "Run as an Administrator.")
SPRING CLEAN
 
Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check




Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
 
Malwarebytes.  Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?
Keep safe  :wave:

Dorian Saignren

  • Guest
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #20 on: March 09, 2011, 05:15:14 PM »
Alright, Puran DeFrag doesn't seem to want to complete the whole "filling gaps" portion, keeps halting at around 45%.  I'm gonna try do it again anyway overnight sometime.  Plan to update everything today also.

On a side note, I'm not saving cookies for some reason.  Well... some are, some aren't.  Like the stay signed in function on this site, and the threads I've read on the dragonage wikia forums (shows them all as new, even if I just read them)  but it remembers my password for my roleplaying forum, and not for deviantart and gmail.  Not sure if this is an allowance issue or a feature or a symptom... it hasn't become enough of a hassle for me to investigate my settings yet XD

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #21 on: March 09, 2011, 07:31:23 PM »
Not saving cookies is probably due to a setting within your browser - which one do you use

Dorian Saignren

  • Guest
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #22 on: March 09, 2011, 07:37:57 PM »
Firefox.  It did everything pretty well before all this lol, aside from the virus activity.  But now that it's all done it's cutting corners on what it saves and what it doesn't lol

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Finally got ComboFix to work (title updated as of ~Mar4th11pmEST)
« Reply #23 on: March 09, 2011, 07:45:55 PM »
OK I will let one of the firefox boys handle this as I never use it