Combofix messed up autorun.inf

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by skidajmo, Jan 30, 2011.

  1. skidajmo

    skidajmo Private E-2

    After I used Combofix my hard drives lost capabilities of having ICO files on drives through auturun.inf.
    I had one autorun.inf file for each partition (or USB or external had-drive) with this line:
    [autorun]
    ICON=AUTORUN\Samsung.ICO (or WD.ICO, Seagate.ICO, whatever...)
    I still have those autorun.inf files and icons but they don't work, I tried a lot of things but without success. Combofix messed up that feature badly.
    Is there any way to repair that, I preferr using those autorun.inf files, since I'm very cautios and I'm not threatened by viruses through that feature.
    Combofix also unhid some of my hidden folders (who're hidden by default) no matter what're settings in windows for hidden files.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Who asked you to run ComboFix to begin with and why? It is not something you should be running without the guidance of a malware removal expert. Also this is not a malware problem!

    ComboFix removes the ability to use autorun.inf file because they are a very large cause of infections and spreading of infections. Just about every malware removal expert will tell you that you need to disable autoruns as part of your protection plan. Why do you need to use an autorun.inf file to display an ico file and is it really worth compromising your security?

    View of hidden/system files is also enabled as part of ComboFix and it is also a standard procedure during malware removal to help uncover hiding malware files and folders. Uninstalling ComboFix will restore them back to defaults but this will also remove any backups that ComboFix made when you ran it so you may wish to hold off on doing that right now.

    Try running the below with fixes autoplay features. Not sure it will fix autorun features though.

    http://www.microsoft.com/downloads/en/details.aspx?familyid=c680a7b6-e8fa-45c4-a171-1b389cfacdad&displaylang=en
     
  3. skidajmo

    skidajmo Private E-2

    My friend's computer was badly messed up with different pests so I wanted to try it on my computer before I attempt to fix his one, but I didn't know that it (combofix) turns system inside-out. It's a tool for let's say "last attempt" before reinstallation. I used to fix any issue with Malwarebytes' AM so far. Actually I worked as computer serviceman for a long time but never used tool as combofix. Yeah I like those icons, I didn't have any problem with viruses or whatsoever because I almost never bring flash memory from other sources. I already tried that Microsoft's fix and it didn't work.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not really true either but it is a tool that needs be only run under expert supervision and other things need to be run before using it. It should never be run just for the heck of it or to test how it works ;). It has great power and with that great power there are sometimes difficulties that arise. And like many scanners, it also has its own share of false positives; however, the change to autoruns is not really considered a false positive. It is actually considered a necessary change to provide proper security and to also automatically fix several hundred if not thousands of forms of autorun infections.

    MBAM is a great tool but it cannot fix every malware problem that exists these days. Not even close which is why forums like this exist. :) MBAM is one of the tools we also use in our standard cleaning process.

    Attach the log from ComboFix. (See: HOW TO: Attach Items To Your Post )

    Did you try using System Restore?
     
  5. skidajmo

    skidajmo Private E-2

    Yeah but it doesn't work.

    Ok here's the Combofix log in attachment
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you run ComboFix with a /u command line option? It is not even valid anymore to use that. That was the old command to uninstall it too.

    Did you run ComboFix more than once (it looks like you did) or did you run it with the /u option the first time?

    Did you notice that it said
    It is possible that you have more files infected if regedit.exe was/is infected.

    I see nothing in combofix showing that it deleted any autorun.inf files so it may just be registry settings that were modified. ComboFix may have automatically made changes like the one in the below link to disable autoruns but I'm not sure why a System Restore would not undo those registry changes.

    Disabling AutoRuns
     
  7. skidajmo

    skidajmo Private E-2

    I ran Combofix twice. First time normally and second time with /u option (I tried to uninstall it but it certainly was old command as you said) and third time I uninstalled it with /Uninstall option. I don't know but system restore point doesn't work for me, maybe because it was turned off before I started Combofix. Well there is certain system restore point but couldn't get those settings back with it.
    It's somehow strange that it reports regedit.exe infected. Could it be possible result of changing some settings manually? I mean it's nothing much just common proven registry changes for some programs. I keep my PC really clean and have not much chance to get infected. Malwarebytes' and Kaspersky come always clean after the scan.
    Ok could you make one reg file for WinXP to get my AutoRun capability back? I can disable it easily if I have to... Thanks for your support.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was also not a good thing to do because when you did this, you deleted the backups that ComboFix created.

    No. It is more likely that you have infected system files or you have versions that do not match the version of Windows that you are running. Just because MBAM and Kaspersky do not find any problems, it is not a guarantee that you are clean. Based on your ComboFix log you have other non-valid sizes for files or you have never properly updated Windows. One file shown that is not expected is Windows Explorer
    Code:
    2008-04-14   975872  [6.00.2900.5512] c:\windows\explorer.exe
    2008-04-14   975872  [6.00.2900.5512] c:\windows\system32\dllcache\explorer.exe
    Likely will not work since I really have no way of knowing what some of your settings were to begin with which is why backups of the registry are also recommended in the link I gave you.

    It is possible that the Erunt ( registry backup tool ) that ComboFix makes use of still exists ( that is uninstalling ComboFix may not have removed it ). You may be able to do something like below with your Windows XP Pro boot CD.

    1. Restart your computer
    2. Before Windows loads, you will be prompted to choose which Operating System to start
    3. Use the up and down arrow key to select Microsoft Windows Recovery Console
    4. You must enter which Windows installation to log onto. Type 1 and press enter.
    5. At the C:\Windows prompt, type the following bolded text, and press Enter:
    cd erdnt\Hiv-backup
    6. At the next prompt, type the following bolded text, and press Enter:
    batch erdnt.con
    7. The Erunt backups will begin copying.
    8. At the next prompt, type the following bolded text, and press Enter to reboot your PC and remove your boot CD and boot normally
    exit


    If that does not help, the only option that may work is a Windows Repair and if not, then a reinstall.
     
  9. skidajmo

    skidajmo Private E-2

    Ok haven't tried with that registry backup restore over recovery console but I deleted value in this registry line: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
    @="@SYS:DoesNotExist"
    And AutoRun works now again (at least for removable drives, haven't tried it with hard drives but I think it should work now).
    Do you have any tips for getting back those hidden folder settings, without doing that manually ofc? :D
     
  10. skidajmo

    skidajmo Private E-2

    Sorry for making so many posts but I just found "hidden folders" registry tree where Combofix edited that all hidden folders are unhidden by default no matter what's the setting:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

    I just put CheckedValue and DefaultValue both to 1 and it's as it was before. You can hide and unhide hidden folders normally. I hope this helps someone else too...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Glad to hear you have it worked out.

    Uninstalling ComboFix automatically rehides things.

    Also running our cleaning procedures, help you/us see the registry settings to make changes to in necessary. Our cleaning process also unhides things when run and then when we get to final instructions, we rehide everything during the cleanup. In the future, it you have malware problems, it would be best to follow the instructions in the below:

    READ & RUN ME FIRST. Malware Removal Guide

    However since you have unusual and insecure desires to have autorun work, you should not run ComboFix since it will always change this by default. But do note, that to remove or even detect quite a few infections, ComboFix is a necessity.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not the correct values for these keys. CheckedValue should be 1 and DefaultValue should be 2.

    There are many keys that are involved with various aspects of hiding or unhiding files and folders. The below is a list of them but the first registry key listed, is shown with values used to unhide files, system files, and file extensions which is desirable during malware cleanup and also a more desireable state to normally run with. Otherwise you allow malware to too easily hide from view.

     
  13. skidajmo

    skidajmo Private E-2

    Thank you!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds