We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

ComboFix error but have Windows XP?

Options
2»

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Download and run the FREE version of DR WEB
    http://www.freedrweb.com/download+cureit/gr/
    Turn your anti virus OFF
    Click CANCEL to the 'Would you like to read purchase terms now?' message
    Click START click OK
    It will auto QUICK scan
    After that set to scan the WHOLE computer and press the 'play' icon

    ***DO NOT UPGRADE TO FULL VERSION***
    :idea:
  • turbobob
    turbobob Posts: 1,500 Forumite
    edited 5 April 2010 at 11:55AM
    Mac1977 wrote: »
    Is there a problem trying to use Dr Web Live CD if you use Windows as the OS? The user manual says Dr Web is built on Linux OS.

    I've downloaded the file and am trying to write it to a CD-R but keep getting a message to insert a disc?

    Its a live CD which is based on Linux. Its designed to work with Windows installations. It'll work even where infections are so bad that you can't boot into Windows properly, or where the virus is stopping any Windows antivirus software from working.

    To make the CD make sure you're burning a disc image from the file (.iso files are disc images) and not simply copying the file to a CD. If you don't have any on your PC already you need ISO burning software e.g. http://www.imgburn.com/

    Note I tried the Dr Web live CD for myself and on my machine there was a problems as in graphical mode it would not recognise my USB keyboard or mouse. I had to use safe mode unfortunately.

    I see Alienrik telling you to do something else. You should probably go with that as I'm not an anti virus expert.... I just found that video when searching for info on the "Virut" virus.
  • Mac1977
    Mac1977 Posts: 80 Forumite
    OK, followed AliEnRIK's advice. Quick scan found nothing but full scan identified this;

    Object: A0326591.exe
    Path: C;\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP873
    Status: Probably BACKDOOR.Trojan

    No option to select Cure so assuming I Delete?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Yep, remove it
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Did you UPDATE malwarebytes and run a FULL scan then REMOVE all those items you found originally?
    :idea:
  • Mac1977
    Mac1977 Posts: 80 Forumite
    Think I did, but to be honest I seem to have done so many scans over the last few days on different things. Am posting from work so if you recommend anything else I can do at home later.

    Thanks.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Well id be following post #16 obviously

    Then id run a general cleanup ~
    Download CCLEANER
    http://www.piriform.com/ccleaner/download/slim
    Run the CLEANER scan (UNTICK 'cookies')
    Then run the REGISTRY scan (Backup the registry when it asks)

    reboot

    Download GLARY UTILITIES
    http://www.glaryutilities.com/download/gusetup_slim.exe
    Run the ONE CLICK scan
    Goto MODULES / SYSTEM TOOLS / WINDOWS STANDARD TOOLS / then run SYSTEM FILE CHECKER
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.8K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.