This thread's last reply is from May 6, 2008, 5:55 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Katana
Couple of questions for you ...
did ComboFix reboot the machine ?
did you allow CF to continue after installing Recovery Console.
does Recovery Console boot menu appeared during boot-up
Killiney
No, CF didn't reboot the machine, it had installed the recovery drive and then proceded to scan the machine and finished with a log, then when the log came up on the screen, the entire start bar and the blue bar at the bottom of the screen with the sys tray in disappeared completely. I allowed CF to continue after installing the recovery console. and the recovery console came up as a menu in the reboot screen.
Katana
Please try this
1. Restart your computer
2. Before Windows loads, you will be prompted to choose which Operating System to start
3. Use the up and down arrow key to select Microsoft Windows Recovery Console
4. You must enter which Windows installation to log onto. Type 1 and press enter.
5. At the C:\Windows prompt, type the following bolded text, and press Enter:
cd erdnt\subs
6. At the next prompt, type the following bolded text, and press Enter:
batch erdnt.con
7. The erunt backups will begin copying.
8. At the next prompt, type the following bolded text, and press Enter:
exit
Windows will now begin loading.
Please let me know if this works
Katana
You can do it any way you like, CD, DVD external hard drive, USB/Flash drive.
As long as it is not on the drive inside the computer, anywhere else is fine.
Killiney
Hmmm. I've been thinking, would it be easier to get a new laptop? I don't like the one I've got and its not capable of running all the programs for college and stuff, and it gives me an excuse to save up lol
Katana
In some respects, a new machine is always worthwhile.
It depends on when you would be able to get it, I would suggest copying your important files in the next week or so to be on the safe side.
Killiney
That I can do.
Is there any way of checking to see if there's anything still on the machine?
Killiney
ActiveScan log
;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-04-29 21:56:38
PROTECTIONS: 1
MALWARE: 20
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG Anti-Virus Free 8.0 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00046186 W32/Alcan.A.worm Virus/Worm No 0 Yes No C:\Documents and Settings\Nathan\My Documents\LimeWire\Saved\Windows Media Player 11.zip[Setup.exe]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@casalemedia[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@atdmt[1].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@tradedoubler[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@fastclick[1].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@mediaplex[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@com[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@statcounter[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\[removed][2].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@apmebf[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\[removed]-sys[1].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@advertising[1].txt
00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\[removed][1].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\[removed][1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@questionmarket[1].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@zedo[2].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Nathan\Cookies\nathan@adrevolver[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
182048 HIGH MS07-069
176382 HIGH MS07-057
170907 HIGH MS07-046
170906 HIGH MS07-045
170904 HIGH MS07-043
164913 HIGH MS07-033
160623 HIGH MS07-027
150253 HIGH MS07-016
;===================================================================================================================================================================================