Page 2 of 5 FirstFirst 12345 LastLast
Results 11 to 20 of 48

Thread: Malware/Virus won't stay gone

  1. #11
    Member
    Join Date
    Sep 2008
    Posts
    83

    Default

    Safemode fails on MUP.sys. Reboot loop. With WinPE I don't see a log file in C:\. I do see a Qoobox folder with many files.

  2. #12
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Ok good.
    if there is a "DeQuarantine" Log present in the Qoobox folder, copy/paste the contents of that document back here in your next post.

  3. #13
    Member
    Join Date
    Sep 2008
    Posts
    83

    Default

    There is no DeQuarantine log to be found. Couldn't find anything relevant in the C:\Cypher folder either.

  4. #14
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Ok i need to try and figure this out i will get back to you as soon as possible.

  5. #15
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Hi jezzzzy.
    Ok a couple of questions.
    1. Did you install the Recovery Console before you ran ComboFix?
    2. Do you have an have a XP CD-ROM?

  6. #16
    Member
    Join Date
    Sep 2008
    Posts
    83

    Default

    1. yes
    2. yes

  7. #17
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Hi jezzzzy .
    Good lets try this.

    1. Restart your computer
    2. Before Windows loads, you will be prompted to choose which Operating System to start
    3. Use the up and down arrow key to select Microsoft Windows Recovery Console
    4. You must enter which Windows installation to log onto. Type 1 and press enter.
    5. At the C:\Windows prompt, type the following bolded text, and press Enter:

    cd erdnt\subs

    6. At the next prompt, type the following bolded text, and press Enter:

    batch erdnt.con

    7. The erunt backups will begin copying.
    8. At the next prompt, type the following bolded text, and press Enter:

    exit

    Windows should now begin loading.
    Please post pack and let me know how your PC is performing now.

  8. #18
    Member
    Join Date
    Sep 2008
    Posts
    83

    Default

    First try ended in blue screen
    stop: 0x0000007B(0xF7CAE524,0xC0000034,0x00000000,0x00000000)

    Second try the same.

  9. #19
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Hi jezzzzy.
    I am going to have to consult someone about this, I've not seen this happen before.
    I will get back to you as soon as possible.

  10. #20
    Visiting Fellow
    Join Date
    Nov 2009
    Location
    Land Of The Leprechauns
    Posts
    461

    Default

    Hi jezzzzy.
    Question did you install any Windows updates after the ComboFix run?
    Last edited by Cypher; 2010-02-17 at 11:09.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •