Problem with Combofix stuck at please wait

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by John Clark, Jan 9, 2009.

  1. John Clark

    John Clark Private E-2

    Hello,
    I've been following the instructions posted here with success getting logs until getting to the point of installing and running combofix.

    Combo fix installed and ran as the instructons on bleepingcomputer.com and combofix instructed that it was going to reboot. After reboot, I logged back in and the combofix window just says "Please wait." It's been hung here for quire some time with very little hdd activity. Searching about combofix brings results where people say not to run combofix without specific intructions to do so. I was simply following the instructions in the FAQ.

    How do I get out of this hung combofix?

    Thanks,
    John
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Reboot into safe mode if you can......see if you can run the other scans and get us the logs.
     
  3. John Clark

    John Clark Private E-2

    Tim,
    Thanks for the reply...I should have posted back sooner. I'm a bit of a forum junky myself (mod over at blackberryforums.com)

    Anyway, I was able to exit out of the combo fix and the computer restarted normally. When it hung, I googled more about combofix and got lots of "reload windows" results, so I got a little worried. After that I quit the process and just used the pc for a while and the machine seems to be clean and working nicely. Those are great instructions. Kudos for all the work involved in creating the posts.

    The one thing I did this time that didn't occur the last time I used the instructions (successfully) was that combofix asked if it could update itself. I didn't see anything about that in the instructions so I just let it update.

    Thanks for the reply,

    John
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having malware issues?
     
  5. John Clark

    John Clark Private E-2

    I was...page redirects and popups. I also had some worm that caused an error when opening up drives in My Computer. It said "c:\resycled\boot.com is not a valid win32 application." I'm usually pretty careful but caught something anyway...

    Running your directions got rid of everything. I used it on another computer 6-8 months ago with no issues.
     
  6. John Clark

    John Clark Private E-2

    Also, when running MGTools the GetRunKey.bat file hangs on:

    "Note: Ignore any error messages about not finding registry keys! Just wait for the program to finish running"

    I tried running the other .bat files separately and got logs from the other files but this one doesn't want to run.

    So, if I was going to post logs for you I'm missing the combofix logs and GetRunKeys logs. I can post the rest if you'd like to take a look. I wasn't going to trouble you with the logs since things seem to be fixed, though. :)
     
  7. John Clark

    John Clark Private E-2

    Ok, I edited the GetRunKey.bat and changed echo off to echo on so I could see what's hanging.

    It hangs on the following:

    Code:
    
    C:\MGtools>REM Check for Trojans from Haxdoor family.   Some of the related file
    s are also:
    
    C:\MGtools>REM==================================================================
    ==========
    
    C:\MGtools>C:\MGTools\grep -U -i -q "avpe" C:\MGTools\temp\xlmsysc.txt
    
    C:\MGtools>if ERRORLEVEL 1 GOTO  Haxdoor1
    
    C:\MGtools>C:\MGTools\grep -U -i -q "avpx" C:\MGTools\temp\xlmsysc.txt
    It never leaves this spot in the process. Don't know if it helps or not...
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Post the other logs for me to check.
     
  9. John Clark

    John Clark Private E-2

    Here are the logs I was able to get:

    The MGLogs.zip is not the automated zip file created. I created it and includes as many logs as I could get by running the individual .bat files that were expained would run in the instructions.

    Thanks for helping!

    John
     
    Last edited by a moderator: Jan 19, 2009
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No it isn't...it is here:
    Code:
    C:\
    mglogs.zip    Jan 13 2009       44379  "MGlogs.zip"
    
     
  11. John Clark

    John Clark Private E-2

    Ok...well, here's the one it created but never finished. I figured the one I gave you had more info.
     
    Last edited by a moderator: Jan 19, 2009
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What error message do you get? Are you making the agreement for HJT to run?
     
  13. John Clark

    John Clark Private E-2

    I posted the message I got and where it hung. I also turned echo on so I could see what was hanging and posted that above, as well. I just tried to run it again from scratch and it blue screened.

    I'm no longer having any issues after running what's posted in the instructions, though. However, I appreciate your time!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...that is just dang rude of it!! :)

    As long as your malware scans are removing the infections and you are not seeing them remaining in your system, then I guess all is well.

    If you are not having any other malware issues, then:

     
  15. John Clark

    John Clark Private E-2

    Thank for the help, Tim!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...safe surfing. :)
     
  17. John Clark

    John Clark Private E-2

    Tim,
    Would it be possible to have my logs deleted? There are few tidbits of info contained in them that should stay private.

    Thanks,
    John
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Done. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds