![]() |
|
08-08-2012
|
16 | |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
Ran it and it found some thing called akamai, so I quarentined it. |
|
|
08-08-2012
|
17 |
|
don't call it a comeback
Join Date: Sep 2011
Posts: 8,268
|
|
|
08-08-2012
|
18 |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
@fp4 did the step 3 combo fix thing, now whenever I try to open any program I get the error "Illegal operation attempted on a registry key that has been marked for deletion"... How do I fix this? oh btw i was wrong when I thought the virus was gone think I might try a system restore ok system restore seems to have fixed the problem with programs not working. not sure if virus is gone... ran tdss killer and its back -_- |
|
08-08-2012
|
19 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
Run ComboFix one more time, the virus likely hijacked the registry key that's accessed when you open programs.
|
|
08-08-2012
|
20 |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
since I just did a system restore would I have to run it twice? should I set up another system restore point? I have a weird feeling combofix had an error messing with the registry... I would think the system restore would have brought back the virus. What stops it from screwing my registry again? |
|
08-08-2012
|
21 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
System Restore just restores your registry, not files. If the virus made registry keys and it was in your registry, it is likely a harmless key pointing to a non-existent virus file.
|
|
08-08-2012
|
22 |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
seems like combofix is stuck at preparing the log report and its telling me not to open any programs until its done. edit: oh ran it again, same registry error... guess I gotta do the system restore again... |
|
08-08-2012
|
23 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
Well if it happens when it's doing the log report then it's not a big deal. Sounds like your virus is gone though.
|
|
08-08-2012
|
24 |
|
Registered User
Join Date: Dec 2011
Location: Blacksburg, Virginia
Posts: 5,459
|
|
|
08-08-2012
|
25 |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
|
|
08-08-2012
|
26 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
Open a cmd prompt and do these commands: diskpart list disk select disk 0 list partition Take a screenshot and show me the partitions it lists. Example: http://i.imgur.com/NqE8k.jpg |
|
08-08-2012
|
27 |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
here.
|
|
08-08-2012
|
28 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
Run the command: ipconfig /all > connection_info.txt Then go into your user folder, and paste the contents of connection_info.txt on here. |
|
08-08-2012
|
29 | |
|
The Unwanted Critic
Join Date: Sep 2011
Posts: 3,639
|
did it without the connectioninfo part and got this: wait my bad misread PHP Code:
|
|
|
08-08-2012
|
30 |
|
maymay ambassador
Join Date: Aug 2011
Posts: 1,508
|
and TDSSKiller came up clean? I will have to look more into the virus. Run HiJackThis: http://sourceforge.net/projects/hjt/ and post a log. |