Malware stops combofix.exe from running

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by capadotia, Apr 12, 2009.

  1. capadotia

    capadotia Private E-2

    Hi,

    I hope someone can help me. I have some malware on my machine. I have been going through the malware removal guide posted here and am stuck on the combofix.exe step.

    When I try to run the program nothing happens. Also, when I try to run regedit or the command prompt, the windows shell (explorer?) restarts because all the icons on my desktop refresh but nothing happens otherwise.

    Any ideas?
     
  2. capadotia

    capadotia Private E-2

    A quick update. I finally got combofix to run by downloading from another machine and copying it directly to hard drive of the affected pc.

    Can some malware corrupt downloaded software?

    Anyway, I ran combofix and it appears to have fixed my machine. Keeping my fingers crossed. I can now run regedit and dos command line.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I strongly suggest that you complete ALL instructions in the READ & RUN ME and then attach the 4 requested logs so we can check to make sure you are clean.
     
  4. capadotia

    capadotia Private E-2

    Thanks for taking the time to help me. I really appreciate the existence of this site. I never realized just how horrible and evil this malware can be. I thought all that was needed was a quick scan and it would be done.

    I have attached 3 of the 4 scans you requested. I ran the Super Anti spyware scan twice. The first time it found stuff and deleted it. The second time I ran it - it came up clean. I can't find where the log file for this is located but I know that it didn't find anything the second time through.

    Thanks again.
     

    Attached Files:

  5. capadotia

    capadotia Private E-2

    Well, it is back. Not sure if this is the same one but I think it is different.

    Combo fix won't hurt it now. Combofix won't reboot the pc now. The icons on the desktop seem to turn off for a few seconds and come back on like the shell is restarting. I downloaded the latest combo fix and it still didn't work.

    I went through the whole process again and here are the log files it generated. Any help would be appreciated.
     

    Attached Files:

  6. capadotia

    capadotia Private E-2

    OK. Combofix didn't work but MGTools seemed to do the trick. I rebooted and I can use regedit now and start a dos session. The log files from this latest infestation are attached to the previous message in this thread. Hopefully, the pc is clean now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We have a little more to do.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. capadotia

    capadotia Private E-2

    Thank you so much for taking the time to help me!!! You are awesome and this site is amazing!

    Anyway, hopefully this is the end of this. I did what you requested and combofix ran correctly this time and rebooted the pc by itself.

    I have attached the log files as requested. Does this particular infection have a name? I would be interested in learning more about it.

    Thanks again.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Not really and as you can see nothing detected it accept our manual steps of reading the logs. ;)

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. capadotia

    capadotia Private E-2

    Sounds good. Thanks again for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  12. capadotia

    capadotia Private E-2

    Hi,

    This thing came back again yesterday. I re-ran combo fix with the script you gave me and it seems to have fixed it.

    I have no idea where it keeps coming from. We never go to anywhere but legitimate sites. Could it be be hidden somewhere in our back up files? If so how could I find it? I turned off restore, rebooted and turned it back on as suggested in the guide. We have Zone alarm anti virus and the paid version of super anti-spyware with the real time scanner but nothing seems to catch it before it infects the system.

    Is there anything I can do to find out where it is coming from?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you follow 100% of the instructions I gave you??? Did you complete instructions the below link?

    How to Protect yourself from malware!


    Your PC was not properly protected. No protection or weak protection means you will get infected again.


    Note that this infection will not always use the same driver names, file names or folders.
     
  14. capadotia

    capadotia Private E-2

    Yes, I followed all of your instructions exactly and carefully.

    The only thing I neglected to do in the "protecting yourself from malware" part was disable the autorun feature. I had read that part but forgot to implement it. I will do that now.

    The machine seems to be working properly now however.

    My wife uses this machine to update several websites that she maintains. Twice now someone has reported to her that his mac is saying there is malware on one of her sites. She replaces the index page and then everything seems fine. But now that I think of it, the previous infections on her machine seem to be related to this. I thought that maybe the site was getting the infection from her machine but could it be that her site is periodically being hacked?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Infected websites are not something we can help you with. Sometimes it is poor security on the servers and sometimes it is security holes in the software used to due the web design or the web design itself may have security holes. If this becomes an issue, you could try looking for help in the Programming Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds