Change font size
It is currently Tue Jul 22, 2014 9:54 pm


Post a new topicPost a reply Page 1 of 1   [ 6 posts ]
Author Message
 Post subject: Combofix : Safemode or not ?
PostPosted: Sat Sep 03, 2011 8:35 am 
User avatar

Joined: Tue Jul 07, 2009 4:02 am
Posts: 412
Location: Leeds, England.
Hiya.
An interesting point brought up in another post, whereby it is suggested combo fix is run in normal mode as opposed to safemode. (Ref A1C-James, cheers)

Yes or No.

I always run it in safe mode as I believe it is able to detect nasties normally hidden during normal operation. Also I believe it runs into problems with loaded AV programs.

It is suggested that running in safe mode, with the latest rootkit ZeroAccess, can do more damage than good.

I thought it was a safe mode only program. Am I wrong ?

Regards.


Sent from my iPad using Tapatalk ........ Whilst proclaiming the machine fixed, grabbing the cash and running like hell.

_________________
Proclaim the machine fixed, grab the cash and run like hell !


Top
 Profile  
 
 Post subject: Re: Combofix : Safemode or not ?
PostPosted: Sat Sep 03, 2011 10:45 am 
User avatar

Joined: Fri Feb 12, 2010 1:34 pm
Posts: 323
Location: Rushden, Northants
I only run combofix in safe mode when I have to, i.e. I will always run it in 'normal' mode, as a lot of 'infections' these days only come out in specific user accounts (like the hide desktop and documents types).

_________________
--
With Friendly Regards,
Wim Wauters T/A Unisoft Design

IT network and systems administrator
for professionals and small to medium size businesses
http://www.UnisoftDesign.co.uk


Top
 Profile  
 
 Post subject: Combofix : Safemode or not ?
PostPosted: Sat Sep 03, 2011 4:33 pm 
User avatar

Joined: Tue Jul 07, 2009 4:02 am
Posts: 412
Location: Leeds, England.
Interesting.

I thought it wasn't user specific.

I thought that running it in safe mode under the "admin" profile meant that its search would "propagate" through to the other user profiles.

Do I understand this correctly?
Does it have to be run separately on each user profile ?

Or have I got wrong (again:))

Cheers.


Sent from my iPad using Tapatalk ........ Whilst proclaiming the machine fixed, grabbing the cash and running like hell.

_________________
Proclaim the machine fixed, grab the cash and run like hell !


Top
 Profile  
 
 Post subject: Re: Combofix : Safemode or not ?
PostPosted: Sat Sep 03, 2011 5:46 pm 
User avatar

Joined: Mon Sep 06, 2010 1:56 pm
Posts: 334
Location: Oshawa, Ontario, Canada
Hey bertie,

Combofix is user specific because of the way the windows registry works. As an example loading any profile, the HKLM hive of the windows registry is always accessible since it stores all the vital system information but the HKCU hive only loads per individual profile. Also the HKCU registry hive is not located in the C:\windows\system32\config folder but rather in each separate users file folder.

Actually this is not entirely true as the all User profile hives are actually loaded into the windows registry but not under HKCU. All user profiles that are active and non active are located within the HK_USERS extension which are uniquely named as S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX. The S-X-X-X numbers represent the profile type, security access, and restrictions.

Since each user profile is uniquely named this would make it a problem for combofix to isolate and chooses only to read the HKCU hive. However, this is merely a delema as there is indeed a way to bypass this problem. In windows XP you can always right click on combofix and choose "Run As" then enter the credentials of the user you wish to scan. This is also possible with windows 7 but you need to be running a non restricted admin account. you can access the default administrators account.

you can access the non restricted admin account by opening command prompt with administrator privileges then type in net user administrator /active:yes . however this account is disabled specifically to avoid infection so when your done be sure to repeat the process and type in net user administrator /active:no

_________________
A1Computers
905-432-6862
Oshawa, Ontario, Canada
Sales@A1Computers.ca
http://www.a1computers.ca


Top
 Profile  
 
 Post subject: Re: Combofix : Safemode or not ?
PostPosted: Sun Sep 04, 2011 8:28 pm 

Joined: Mon Sep 20, 2010 10:13 pm
Posts: 22
I only run it real mode after I have manually removed malicious items with a ERD disk. Just need to make sure you disable your internet protection before you run it.


Top
 Profile  
 
 Post subject: Re: Combofix : Safemode or not ?
PostPosted: Mon Sep 05, 2011 5:45 pm 
User avatar

Joined: Mon Sep 06, 2010 1:56 pm
Posts: 334
Location: Oshawa, Ontario, Canada
yeah I love ERD and MSdart. they are extremely useful and powerful tools. I got the whole set.

_________________
A1Computers
905-432-6862
Oshawa, Ontario, Canada
Sales@A1Computers.ca
http://www.a1computers.ca


Top
 Profile  
 
Display posts from previous:  Sort by  
Post a new topicPost a reply Page 1 of 1   [ 6 posts ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Learn How To Fix Laptops



Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
610nm Style by Daniel St. Jules of Gamexe.net
Change colors.