Combofix won't run

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by folkc, Nov 13, 2013.

  1. folkc

    folkc Private E-2

    does anyone know why my combofix won't run? i know its a virus but how can i force it to run?

    thx in advance
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How long ago did you download it? You should not be running it on your own without instructions. Can you follow these instructions please and let me know whether you can run any of it? :)

    READ & RUN ME FIRST - Malware Removal Guide
     
  3. folkc

    folkc Private E-2

    i tried the read & run me but hitman pro and mg tools do not run correctly here is the hijack log:
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What errors do you get whilst trying to run them?
    Did Malware Bytes run?
    Did RogueKiller run?
     
  5. folkc

    folkc Private E-2

    malware bytes ran and rogue killer as well so did kapersky but im still infected. hitman couldnt upload files to 'scan cloud' and mg closes suddenly midrun
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then can you attach the logs from the programs that did run then please.

    And in place of MGTools, try this:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. folkc

    folkc Private E-2

    just finished running otl. it took very long but its because of the virus. it kept freezing. i got all the logs but i coulnldnt find hitman log.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
    [2013/11/13 14:47:59 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
    [2013/11/12 18:00:54 | 000,069,895 | ---- | M] () -- C:\Users\J()HN_D()UGH_\AppData\Local\dfl30z32.dll
    [2013/11/08 21:59:38 | 000,000,420 | ---- | M] () -- C:\ProgramData\i30bebgfjac.dat
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Run OTL normally now, just a scan now fix, and attach that log too.

    Now are you able to run Hitman and MGTools?
     
  9. folkc

    folkc Private E-2

    MG tools still refuses to run. first it says unable to download. then i try to run it (instead of download as) right from majorgeeks and nothing happens. then i tried to rename it and it downloads but it does not run (double click right click - nothing)

    hitman pro ran but doesnt seem to pick anything up.
     

    Attached Files:

  10. folkc

    folkc Private E-2

    sorry i didnt understand part of your reply:

    'Run OTL normally now, "just a scan now fix", and attach that log too'


    so i just clicked 'run scan' on otl in addition to my last reply
     

    Attached Files:

    • OTL.Txt
      File size:
      126 KB
      Views:
      5
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does MGTools run in safe mode? (Use safe mode with networking to download it if necessary)
     
  12. folkc

    folkc Private E-2

    no. im in safe mode now.

    i was able to download mg to root folder from majorgeeks but when i double clicked it and the 'run program' box popped up and i pressed 'run' - nothing happened.

    10 minutes later i right clicked mg and clicked 'run as administrater' - nothing happened - not even a 'run program' box.

    on another note - i checked my task manager and i see 2 'mgtools.exe' processes running and 2 'cmd.exe' processes also running - strange cause i see no other evidence on the screen
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, other than MGTools and Combofix not running, how is the machine behaving? Because they will not run, does not necessarily mean you are infected. There could be other problems causing it.

    What exactly led you to run Combofix anyway?
     
  14. folkc

    folkc Private E-2

    last week i was browsing the internet and started experiencing extremely high cpu usage that got me suspicious. i was unable to run anything without pc freezing from cpu high.

    shortly after i lost my volume, i lost google toolbar, i lost vlc, i lost trouble shooter, i lost cmd and a number of other programs too.

    my task manager showed alot of these programs running through processes but nothing on screen- they've been taken over by something else. i also saw suspicious processes that ive never seen before.

    so i ran combofix and it ran but it took an unusually long time to run - it found my entire system32 folder to be infected and replaced almost the files- i cant locate that log

    i also tried online scanners but they would not run.

    so i ran 'read and run me' from major geeks and it did help but im still infected
    because none of the programs i lost will run, my cmd will not run, my sound drivers delete on reboot, my theme goes to windows classic on every reboot, i get running script errors on every web page and i still have suspicious named processes running

    i suspect my programs (.exe) have been taken over and are being used to spread the virus

    i also suspect that the only antivirus that will work are cmd based or online scanner type and this is why the virus has disabled these from running
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is there a log for combofix directly on the C:\ drive? :confused
    Do you still have combofix downloaded? If so rename it to 4fr7j.com and try and run it again.
     
  16. folkc

    folkc Private E-2

    i cannot find that log

    i do have combofix installed on my system

    i renamed it as you said but when i tried to run it it gets hung up during the extraction process so it will not run

    also at present (amongst suspicious others) there are 11 'conhost.exe' and 11 'iexplore' processes listed in task manager yet i only have this tab in major geeks open

    what is going on?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Normal. It is a tabbed browser and will show multiple processes running. There's also a little article here about the multiple conhost: The story of multiple conhost.exe

    I have only removed a small amount of junk, I never found any malware. I really wish you had that log from combofix showing what it removed or replaced. I wonder if it did some damage. This is why it is never advised to run it on your own.

    I may have to send you off to the software forum, however let's try this:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Is the machineany better?
     
  18. folkc

    folkc Private E-2

    windows repair program got hung up (the same way combofix does) - it will not run pass this - 2 hours now (see jpg)

    this is my only browsing session open - please do not tell me this is normal (see both jpgs)

    please look at my task manager snap shots - whats going on? :cry
     
  19. folkc

    folkc Private E-2

    see attached:
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see this from your screenshot and you can delete it:

    C:\Users\J0HN_~1\Appdata\Local\temp\nsjB15B.tmp

    Do you have ccleaner installed, or another third party cleaner? If so use it to be rid of temp files.

    Also, it appears that combofix is still running, despite the fact you say it is uninstalled. I see signs of it all over the place.

    I do admit you do seem to have alot of conhost processes.

    Are you able to use system restore at all to go back to a point before things went unstable?

    Are you able to use system recovery at all to help?
     
  21. folkc

    folkc Private E-2

    i cannot delete the file specified- it is open. i do have ccleaner but as you know it will not delete open infected files

    i never said combofix was uninstalled. i told you combofix gets hung up- the process runs but it doesnt get past the extraction stage - it gets stuck as does any other useful program

    they're running invisibly not of any use to me

    what appears to be combofix in task manager is not i suspect

    maybe malware using the name for other purpose



    the furthest restore point is just 2 days ago

    have you seriously not seen my issue before?

    i have been using combofix for a long time and it has always saved the day

    if we can see suspicious tmp files in task manager why do progams like malwarebytes and hitman (that are installed on my system already) do not?

    do they suck?

    do you see any other problems in my screenshots?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for it to be uninstalled. Do you know how?
    Well we'll see what happens after CF is removed but they are, from what I can see, related to combofix.

    Damn. So that doesn't help us.

    I've seen lots of unstable machines that certain programs will not run on yes. At the moment, we don't actually know what's wrong with yours, for me to say "Oh, yes... I know how to deal with this..." If you know what I mean. :)

    it's also a double edged sword.... and can cause system unstability, esp. if used regularly by untrained persons.

    Because not every program see's everything... it's why we use multiple scanners.
    Not at all. Sometimes what MBAM misses, superantispyware finds, and so on... or vice cersa.

    Only that you do indeed seem to have alot of conhost processes as already mentioned.

    Are you able to do a Repair Installation? :confused

    Let me know if Combofix is now uninstalled or not.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the original HijackThis log the below multiple instances of ComboFix and A-Aquared were running.
    You need to stop running ComboFix and A-Squared!!!!! Also do the below.


    Uninstall the below:
    • ESET NOD32
    • Any Emisoft software like A-Squared or Emisoft Anti-Malware
    • Also uninstall ComboFix using the below steps which assumes that the filenamed combofix.exe is on your Desktop!!!!!! If not there or not named as such then put the file named combofix.exe directly on your Desktop.
        • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
        • Copy and paste the below into the Run box and then click OK. Note the quotes are required
        • "%userprofile%\Desktop\combofix" /uninstall
          • Notes: The space between the combofix and the /uninstall, it must be there.
          • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    • Now reboot your PC.
    • After reboot delete any of the below folders if they still exist:
      • C:\32788R22FWJFW
      • C:\QooBox
    • Also delete any remaining copies of ComboFix.exe that you have and if you renamed it ( as shown above to iexplore.exe ) then delete the renamed copies too.
    • Now make sure that No Protection Software is running and that UAC is disabled as requested in the READ & RUN ME. If it was not already disabled, you need to reboot after you disable it before trying the below and then disable any protection software again.
    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now download the current version of MGtools and save it to your Desktop folder. Overwrite any previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista, Win7, or Win8, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below logs:
    • the JRT.TXTlog
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds