Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old October 8th, 2009, 03:12 PM
dmcintos dmcintos is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2009
Location: Lawton, OK
Posts: 1 dmcintos User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 55 m 32 sec
Reputation Power: 0
Question Can't stop Combo-Fix from rebooting

I was reading this thread, (Note: thread heading is AntiVirus apps don't work, AntiVirus sites blocked, Spywareguard2008 not deletable) and hoped Combo-Fix might solve my problem with Windows Police Pro hijack virus that won't allow other pgms to run and apparently locks out other antivirus software and even Malwarebytes.

Computer is a Dell laptop running XP Home.

Problem is now ComboFix is in an endless loop. It runs fine, except for one error when starting saying it can't find C:\ComboFix\Update-CF.cmd, but continues to run and finally finding 6 problem files noted as Rootkit files.

ComboFix has detected the presence of rootkit activity and needs to reboot the machine
Kindly note down on paper, the name of each file. We may need it later

c\windows\system32\drivers\gasfkyxstppxmi.sys
c\windows\system32\gasfkyxthwmbdi.dll
c\windows\system32\gasfkybcrienbj.dat
c\windows\system32\gasfkytabvtixl.dll
c\windows\system32\gasfkydyymwwyl.dat
c\windows\system32\gasfkyvnkftilr.dll

The problem comes when I click OK to reboot the process starts all over again automatically. Doesn't matter if I boot to normal mode and log in as the user, boot to Safe Mode and log in as either the user or Administrator account, the program begins again.

Nothing gets fixed. Program finds the files, reboots, runs itself again and finds the files, reboots...

Is there a way to stop the program from automatically running or is something else wrong?

Help...

Update: Finally got the program to stop with Ctrl-Break.
Just out of curiosity I opened Windows Explorer and checked under the folder C:\ComboFix for the .cmd file mentioned but found instead a complete directory of the PC just like I'd get from My Computer and appears to be endless levels. I stopped counting after 10.

Reply With Quote
  #2  
Old December 29th, 2009, 11:35 PM
zenaire zenaire is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2009
Posts: 3 zenaire User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 39 m 21 sec
Reputation Power: 0
Sorry to hear about your problems...But my question is didn't you know that combofix has some warnings...like

"Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again."

Do you have any options to choose like...(Before Windows loads...).Select Microsoft Windows Recovery Console or something like that...

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Can't stop Combo-Fix from rebooting

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap