Combofix disabled usb ports

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nastone, Jun 6, 2010.

  1. nastone

    nastone Private E-2

    My daughter got a trojan malware that redirected her search engine results elsewhere. I read about using Combofix. Ran it. Now none of her usb ports work. can't use the mouse to point and click. I am at my wits end. Tried doing system restore. Says it can't restore system. Tried to navigate her computer using keyboard commands...I'm dense. Got a few of them. Anyone??
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    ComboFix is not something you should be using on your own. Where did you download it from and what instructions were you following for using it?

    What devices are you connection to the USB ports that are having problems and were they plugged in when ComboFix was run? If so, it could be that ComboFix deleted any autorun.inf files found on them since they are used to spread infections and thus can be quite dangerous. However some external devices are not designed to well and run into issues if these files are removed.

    Do you have the log from ComboFix? If so please attach it (See: HOW TO: Attach Items To Your Post )

    Also are you still having redirection issues or other malware problems?
     
  3. nastone

    nastone Private E-2

    I downloaded it from a place called bleepingcomputer.com.
    I had no idea it was not a load and shoot program. It gave me a txt file. But, the computer froze up. I couldn't save it. I know it found a trojan that was the culprit for the mis-direction of urls. I wish we had that problem back without this problem.
    The keyboard works, but is not a usb keyboard. The mouse is the only thing my daughter is using in the usb port right now. None of the usb ports work. I have very little knowledge about using a keyboard to navigate. I did manage to get into some folder and see there was a yellow "Highlight" on the USB item. I've tried going back with system restore...it will not let me.
    I'm sorry I can't be more help.
    The folder was the System Information under System Tools...I think.
    OH. I'm on my computer now. Her computer does not work. I couldn't attach a file from her computer, if I had it.
     
    Last edited: Jun 6, 2010
  4. nastone

    nastone Private E-2

    Hi, it took me a while, but I figured out how to navigate to a folder on her computer using the keyboard and burned the txt files to a cd. There are 2 of them.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it removed the TDL3 infections as noted by the below
    Code:
    Infected copy of c:\windows\system32\drivers\kbdclass.sys was found and disinfected
    Restored copy from - Kitty had a snack :p 
    .
    Based on your logs it did not remove anything else and does not appear to be the source of your USB port issue even though you ran it before the problem began. The file that was replace is however a keyboard driver file and yours was infected with a the TDL3 aka TDSS aka Alureon infection and needed to be replaced. It is possible that the infection itself may have some how cause the issue.

    I believe that you are referring to Device Manager where you may have seen a yellow exclamation point indicating a problem.



    Does the USB mouse work if plugged into the other ports where you say you cannot use the USB keyboard?

    I think it would be a good idea for you to work thru the below procedure to make sure all malware is gone. Skip the part with running ComboFix since it was already run.

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds