Fun times with Windows Police Pro.

Thread Solved

Join Date: Oct 2009
Posts: 37
Reputation: Asezat is an unknown quantity at this point 
Solved Threads: 0
Asezat Asezat is offline Offline
Light Poster
 
0
  #41
Oct 22nd, 2009
Originally Posted by PhilliePhan View Post
OK - Let me know if you are definitely going to do that.
Otherwise there is a ton of other things we would need to do regarding your outdated Java and others, Security Programs, that error on boot (BIOS not found - probably your Promise hard drive controller) etc...

A reformat would render all that moot. Let me know & I can help you with that if you need it. Be sure you can find that Windows disk.
Also, you can use imgburn to burn an ISO of SP3 . . .. Guess you'll cross that bridge when you get to it.

OK - back to the problem at hand:

-- c:\program files\Mail.Ru -- You installed and use this? Just checking.


-- Please delete your copy of ComboFix and download a fresh one to your Desktop
-- Download the attached file CFScript.txt to your Desktop as well
-- Close ALL browser windows and then drag CFScript.txt into ComboFix.exe just like this.

-- Let Combofix run as before and post me that log.

And . . . We'll go from there
PP
I haven't decided for sure yet, but I'm certainly leaning that way. I was thinking about it before this even happened.

Yep, mail.ru is legit. I have a few Russian friends, and it's their IM service of choice. Alexa ranks mail.ru as their 2nd or 3rd most visited site, so it's fairly solid.

Problem: I've disposed of my P2P software, turned off teatimer, downloaded a new combofix, and dropped that little notepad file onto it to start it up. It went through all it's usual motions, started the scan, then... just stopped. I've been sitting at "Complete Stage_2" for the best part of half an hour, with no sign of life from the box itself, and I'm not sure what to do.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 987
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 47
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #42
Oct 22nd, 2009
Originally Posted by Asezat View Post
It went through all it's usual motions, started the scan, then... just stopped. I've been sitting at "Complete Stage_2" for the best part of half an hour, with no sign of life from the box itself, and I'm not sure what to do.
If you didn't touch it or do anything to cause it to stall, then just let it keep running. Overnight if you have to....
If it still hasn't completed, then we'll address that. Sometimes this will happen with some tougher malware, though given the previous runs there may indeed be a stall.
Let's just be patient and see what happens.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 37
Reputation: Asezat is an unknown quantity at this point 
Solved Threads: 0
Asezat Asezat is offline Offline
Light Poster
 
0
  #43
Oct 23rd, 2009
No, I didn't touch it, it just hasn't moved. Same situation, 8 hours later.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 987
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 47
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #44
Oct 23rd, 2009
Originally Posted by Asezat View Post
No, I didn't touch it, it just hasn't moved. Same situation, 8 hours later.
Bloody hell.

I suppose it would be too much to ask for something to go right just once to make things easy on us...... Somebody is laughing at us.

I guess we'll have to power off and reboot. Then try the last step again complete with a fresh download of combofix.
--Rename combofix again at download as you did before to combo-fix, just to cover that base.

Let me know how that shakes out. I won't have another break for a few hours. Will check back then.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 37
Reputation: Asezat is an unknown quantity at this point 
Solved Threads: 0
Asezat Asezat is offline Offline
Light Poster
 
0
  #45
Oct 24th, 2009
Hey again. Apologies it took me so long to get back to you, been busy as hell yesterday evening and this morning :.

Anyway, I re-downloaded combofix and the file, renamed it, etc, and fired it up again. That being about 20 minutes ago, and I'm stuck at the same stage as I was before. Not sure what to do, now.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 987
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 47
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #46
Oct 24th, 2009
Originally Posted by Asezat View Post
Hey again. Apologies it took me so long to get back to you, been busy as hell yesterday evening and this morning :.
No worries - we all have "real lives" to contend with.
I am going to be pretty busy with typical fall chores this weekend + watching sports (don't know if PhilliePhan would give that away across the pond....)

Let's try MBAM
-- Run your MBAM and click the Update tab.
You should at least have Database Version 3027
--Then, run the Full Scan and post me the log. Be sure to have it fix what it finds and go ahead and Reboot when it finishes.

Let's see where that leaves us. Hang in there - I think we are almost to the finish line....

Cheers
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 37
Reputation: Asezat is an unknown quantity at this point 
Solved Threads: 0
Asezat Asezat is offline Offline
Light Poster
 
0
  #47
Oct 24th, 2009
I did figure it was sport-related, though I didn't know know it was baseball .

I can't update MBAM, it just gives me an error (code 732 (0,0)). I tried to download a new db from the link provided, but it gives me a 404 error. I'm stuck with version 2775. Should I run it anyway?
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 987
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 47
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #48
Oct 24th, 2009
Originally Posted by Asezat View Post
I did figure it was sport-related, though I didn't know know it was baseball .

I can't update MBAM, it just gives me an error (code 732 (0,0)). I tried to download a new db from the link provided, but it gives me a 404 error. I'm stuck with version 2775. Should I run it anyway?
Download http://www.malwarebytes.org/mbam/dat...mbam-rules.exe

Run mbam-rules.exe - I'm not sure what database it will be, but definitely more recent than 2775.
Then try MBAM and let's see what it removes.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 37
Reputation: Asezat is an unknown quantity at this point 
Solved Threads: 0
Asezat Asezat is offline Offline
Light Poster
 
0
  #49
Oct 24th, 2009
Apparently "Firefox can't find the server at www.malwarebytes.org." Same result with IE, and opera.

I get the same error on my laptop.
Last edited by Asezat; Oct 24th, 2009 at 6:32 pm. Reason: Added the laptop comment.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 987
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 47
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #50
Oct 24th, 2009
Originally Posted by Asezat View Post
Apparently "Firefox can't find the server at www.malwarebytes.org." Same result with IE, and opera.

I get the same error on my laptop.
That's a bit worrisome - you may have some malware on the lappy, too.....

See if you can access it via Majorgeeks:
http://majorgeeks.com/Malwarebytes_A...ase_d6025.html

PP

EDIT:
Maybe a run of MBAM on laptop is warranted?
Last edited by PhilliePhan; Oct 24th, 2009 at 7:15 pm. Reason: Added info
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC