Forums
Trivial - Hyjal WoW Server Guild :: Forums :: Hardware / Software Discussion :: Software Discussion
 
<< Previous thread | Next thread >>
For Pyro: ComboFix log
Moderators: Pyro411, Dippe, Sarran, Honesty, Icemann, Nashal, Heridfel
Author Post
Dippe
Tue Feb 02 2010, 09:43AM
temptrest

Registered Member #2
Joined: Sun Nov 06 2005, 06:13PM
Posts: 1469
Hey Pyro,

Are you able to diagnose a Combofix log file and tell me what to do as a follow up? I ran it, it removed a few nasty bugs then left me with a log file.


log.zip
Back to top
Pyro411
Tue Feb 02 2010, 12:31PM
Tired Geek


Registered Member #1
Joined: Sat Nov 05 2005, 06:56PM
Location: Howard City, Michigan
Posts: 640
Dippe, I'm taking a look now, I don't use combofix all that much myself, if possible can you check out the following registry key and give me the values of userinit and shell

hklm/software/microsoft/windows nt/current version/winlogon

Shell should be Explorer.exe
Userinit should be C:\windows\system32\userinit.exe "Unless it's NT or 2000 then it'll be C:\winnt\system32\userinit.exe"

“Stand up. Face forward. Hesitate and you will die. Retreat and you will age.”-Zangetsu
Not so Eternal Lowbie anymore



My Gamestop wishlist



Join my Battle Stations Crew on Facebook
http://apps.facebook.com/battlestations/new.php?invite=Piros
Back to top
Website
Dippe
Tue Feb 02 2010, 12:49PM
temptrest

Registered Member #2
Joined: Sun Nov 06 2005, 06:13PM
Posts: 1469
I'll check those keys shortly.

After the atapi.sys was fixed I was able to start up Safe Mode again. yay. A Malwarebytes full scan revealed 2 more trojan files.. I still not sure if those were hiding themselves when the PC was in normal mode or something re-installed them.
Back to top
Dippe
Tue Feb 02 2010, 12:54PM
temptrest

Registered Member #2
Joined: Sun Nov 06 2005, 06:13PM
Posts: 1469
Shell is indeed Explorer.exe
And Userinit points to c:\windows\system32\userinit.exe
Back to top
Pyro411
Tue Feb 02 2010, 02:50PM
Tired Geek


Registered Member #1
Joined: Sat Nov 05 2005, 06:56PM
Location: Howard City, Michigan
Posts: 640
dippe, are you doing the mbam scans from safemode command prompt after you've updated the pattern files and set the options to close IE upon cleanup?

“Stand up. Face forward. Hesitate and you will die. Retreat and you will age.”-Zangetsu
Not so Eternal Lowbie anymore



My Gamestop wishlist



Join my Battle Stations Crew on Facebook
http://apps.facebook.com/battlestations/new.php?invite=Piros
Back to top
Website
Dippe
Tue Feb 02 2010, 05:46PM
temptrest

Registered Member #2
Joined: Sun Nov 06 2005, 06:13PM
Posts: 1469
nay.. Im running things from the Windows Safe Mode environment.

As an update.. I scanned using Spybot, MBam, and AVG all in safemode.. so far the system has not found any further virus.

I didn't want to get you too involved.. was just thinking you had expertise with Combofix and you knew exactly where to look.

Back to top
Dippe
Tue Feb 02 2010, 05:48PM
temptrest

Registered Member #2
Joined: Sun Nov 06 2005, 06:13PM
Posts: 1469
If I set a the owner's permissions to only be able to read and use programs.. and remover her Administrative status.. would that help reduce chances of getting re-infected?
Back to top
 

Jump:     Back to top

Syndicate this thread: rss 0.92 Syndicate this thread: rss 2.0 Syndicate this thread: RDF
Powered by e107 Forum System

All trademarks are ® to their respective owners, all other content is ® e107 powered website.
e107 is ® e107.org 2002/2003 and is released under the GNU GPL license.
{THEMEDISCLAIMER}