Forum Home
Press F1
 
Thread ID: 97556 2009-02-19 22:32:00 Virus Removal Help Blam (54) Press F1
Post ID Timestamp Content User
749464 2009-02-20 10:00:00 Did you reboot after? Speedy Gonzales (78)
749465 2009-02-20 19:36:00 Yep Blam (54)
749466 2009-02-20 21:58:00 Whats F and G??

These entries

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{960ca98b-f417-11dd-9ec4-001c7e33551d}]
\shell\AutoRun\command - F:\2u.com
\shell\explore\Command - F:\2u.com
\shell\open\Command - F:\2u.com

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{960ca98f-f417-11dd-9ec4-001c7e33551d}]
\shell\AutoRun\command - G:\2u.com
\shell\explore\Command - G:\2u.com
\shell\open\Command - G:\2u.com

That file may belong to a rootkit
Speedy Gonzales (78)
749467 2009-02-20 22:51:00 It may belong to his external hard drive?

BTw its really bad now, did a scan with combofix, now computer doesn't start up, just loads, then goes to a black screen..
Blam (54)
749468 2009-02-20 22:56:00 Remove the external hdd

That maybe F whats G?? or is it partitioned or something?
Speedy Gonzales (78)
749469 2009-02-20 23:28:00 It may belong to his external hard drive?

BTw its really bad now, did a scan with combofix, now computer doesn't start up, just loads, then goes to a black screen.. A SECOND combofix scan ???

Hopefully you have system restore enabled - boot from safe mode with command prompt if you can, and run restore back to prior running of combofix, as combofix makes a restore point before doing anything.

The command is C:\windows\system32\restore\rstrui.exe
Seriously though - sometimes depending on just how bad a PC is its sometimes better to save the data and reinstall from fresh - that of course depends on how much time you want to play around with a badly infected system - if its to bad you'll never be sure you got every thing.
wainuitech (129)
749470 2009-02-21 01:35:00 No, it was from the first combofix scan.

System restore was disabled:x
Blam (54)
749471 2009-02-21 01:41:00 Hmmmm only time I have seen combo fix really screw a system is when the viruses / spyware attack some of the system files and basically distroy them.

When that has happened in the past ( and from memory its only been twice out of the MANY times I run Combofix) a repair install gets it going again.

As mentioned before - if a system is so badly damaged - a complete new install maybe best - sometimes you think you have every thing and it turns round and bites you in the backside 5 minutes later.
wainuitech (129)
749472 2009-02-21 01:57:00 Ran Vista recovery CD, and it seems to have fixed it...I'll do a few more scans...
I really want to reinstall, but my friend is very reluctant to do so....

I'll update you on anything

Thanks
Blam
Blam (54)
749473 2009-02-21 02:05:00 OOPS! :o My mistake on the repair install - forgot it was Vista. The repair install works on XP. wainuitech (129)
1 2 3 4 5 6