how rid pc of combofix

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by calvin2a, Dec 12, 2014.

  1. calvin2a

    calvin2a Private E-2

    I see from googling that many have been called upon over the years for help deleting the Qoobox and Qoobox\BackEnv files inherited from the unfortunate use of Combofix which is blacklisted by mywot.com and deservedly so. How do I clean it from my pc? Thanks for any help; I know you are busy.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ComboFix is designed to be run with supervision. You should be able to just right click those folders and delete them.
     
  3. calvin2a

    calvin2a Private E-2

    If only it were that easy, I would not be here. But thanks. No, these files do not allow themselves to be deleted.:wave
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you still have ComboFix installed?
     
  5. calvin2a

    calvin2a Private E-2

    No longer installed. What does it mean "designed to be run with supervision"? This is my personal home pc, not networked, not wifi-ed. I don't even no what ComboFix is but apparently I ran it as some time in the past. Plus I notice it's mentioned on your website.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can't remove it. First you need to re-download it.

    Please download ComboFix to your desktop.

    Make sure it is on your desktop.

    Now:


    • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
    • This opens the Run dialog box.
    • Copy and paste the below text inside the text-field:
      • "%userprofile%\desktop\ComboFix" /uninstall

    • Now press ENTER
    • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
     
  7. calvin2a

    calvin2a Private E-2

    Ok, but ComboFix is attempting to run without being asked and before appearing on my Desktop. It is requesting antivirus and Microsoft Security Essentials be disabled and closed my browser without being asked. It seems that it will not appear on my Desktop until it finishes whatever it is doing. Do you think it is safe to let it run?
     
  8. calvin2a

    calvin2a Private E-2

    What I'm trying to describe, but not very well, is that ComboFix appears to be not merely extracting files and installing itself, but appears intent on running without being asked. Little scary. Ok, I'm a wimp.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let it finish and then you can apply the removal script.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Combofix is a malware removal tool, just so you know. We use it here sometimes. It is a double edged sword in that it's dangerous to use without expert help. But don't be nervous of it being on your system. Tim will continue to assist with helping you remove it anyway. :)
     
    Last edited: Dec 13, 2014
  11. calvin2a

    calvin2a Private E-2

    The downloaded ComboFix.exe file was run.
    During file extraction, it
    a) advised to disable antivirus and MSE which I did,
    b) asked if I wanted an updated version which I declined,
    c) logged my browser (Firefox) off and in doing so somehow changed my default browser from Firefox to IE,
    d) without permission "Attempted to create a new restore point" (i assume that was successful),
    e) without permission "scanned for infected files" (~20minutes),
    f) updated the c:\Qoobox file tree, and
    g) generated a ComboFix.txt reporting successfully completing scan (hidden files: 0), removing some orphans, locking some registry keys, and a bunch of stuff I don't understand.

    However, the uninstall script does not run because no ComboFix folder was generated in Desktop or anywhere else that I can find and I have "Display hidden files? selected.
    So the C:\Qoobox folder is still there and undeletable.
    Maybe I should have accepted the updated version...?...whadya think?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you download it to the desktop?
     
  13. calvin2a

    calvin2a Private E-2

    Hmm, I've long since set a custom folder for all downloads to go rather than the typical default location - %userprofile%\desktop\ComboFix..
    Is the reason ComboFix has left no trail? rolleyesDuh?:-o
    Should I change that and repeat?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I told you to download it to your desktop.....there was a reason for that. Just move it to the desktop and run the script.
     
  15. calvin2a

    calvin2a Private E-2

    Yes, you did tell me that. What you did not realize is that I did not know that had to be accomplished manually.

    However, what I went ahead and did while waiting was to move the downloaded ComboFix.exe file to %userprofile%\desktop...I assume %userprofile%\desktop in my case really means C:\Documents and Settings\me\Desktop. Reran the .exe file, was not given the opportunity to use the upgraded version this time. All else remained the same: no folder left behind by ComboFix for the uninstall script to find.

    I then changed my default download location to C:\Documents and Settings\me\Desktop, re-downloaded to that location, reran, same results. Nothing left behind for the /uninstall to find.

    ComboFix is not installing; it extracts, runs, generates both a Log Report and an undeletable C:\Qoobox folder, opens the Log Report for you, and disappears. There is nothing to uninstall because it doesn't install.

    You wrote that
    ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.In no instance has that happened. The utility asks me to wait while the Log Report is generated, then disappears, and the report launches in notepad.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you ran the script, did it disappear from your desktop? What happens when you try to delete the Qoobox> do you get a message about permissions?
     
  17. calvin2a

    calvin2a Private E-2

    You keep using the word desktop; that is an ambiguous term. The short cut <Windows-D> brings up my desktop whereon lies a shortcut to the ComboFix.exe file located in the C:\Documents and Settings\John\Desktop folder. Nothing has yet to disappear from either my desktop nor from that folder.

    R-clicking on C:\Qoobox folder in Explorer launches a popup dialogue box reading:
    "Cannot delete BackEnv: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use."
    Any attempt to change attributes of this folder or its contents yields "Access denied."

    No message re permissions; i run with Administrative permissions.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I am reading, but possibly misinterpreting is that ComboFix is in a folder on your desktop. Is that right?? It is not directly on your desktop?

    If it is, the path should be C:/user/%userprofile%/combofix

    Now download the latest version of MGtools and save it to your root folder. You should have C:/MGTools.exe. Right click and run as administrator. Let it finish then attach the resulting C:/MGLog.zip.
     
    Last edited: Dec 12, 2014
  19. calvin2a

    calvin2a Private E-2

    MGtools.exe appears to have hung up at "Running analyze.exe" but the attached zip file has appeared in root directory.

    Trendmicro Hijack This is trying to send home an error report...is Hijack This part of MGtools I hope?

    I notice my Recycle Bin is empty; that ain't right. :-(
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hijackthis is pre built into MGTools yes.

    MGTools did not run to completion either because:

    • You did not have protection software disabled
    • You did not right click and run as admin
    • You did not have User Account Control disabled

    Please try again like this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  21. calvin2a

    calvin2a Private E-2

    C:\MGtools\nwktst: No error messages.
    C:\MGtools\GetRunKey: No error messages.
    C:\MGtools\ShowNew: No error messages once I disabled antivirus.
    C:\MGtools\analyse: No waiting this time!-)
    C:\MGlogs.zip attached.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Qoobox\*.*
    C:\Documents and Settings\John\Desktop\ComboFix.exe
    C:\ComboFix
    C:\ComboFix.txt
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  23. calvin2a

    calvin2a Private E-2

    Ok, log is attached.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me if all is OK now.
     
  25. calvin2a

    calvin2a Private E-2

    The C:\ComboFix folder has disappeared.
    The execution file, ComboFix.exe, has disappeared from the C:\Documents and Settings\John\Desktop folder
    and
    the desktop shortcut to it has disappeared.

    However, the C:\Qoobox folder with subfiles still exists and is still undeletable: popup dialogue box reads:

    "Error Deleting File or Folder
    Cannot delete BackEnv: Access is denied
    Make sure the disk is not full or write-protected and that the file is not currently in use."
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  27. calvin2a

    calvin2a Private E-2

    Yes, I saw that "fix" while googling the problem before posting here on Majorgeeks. That procedure does not work in XP where when you r-clk on a folder, select Properties, the only tabs you get are General, Sharing, and Customize. No Properties Security tab.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you copy the full text that I posted in OTM exactly as I wrote it?

    Let's try it again:


    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Qoobox
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
    Last edited: Dec 13, 2014
  29. calvin2a

    calvin2a Private E-2

    :) Alright, looks like you got her done.

    C:\Qoobox folder is gone, moved into the OTM\Movedfiles folder which I was able to delete.

    Do I have permission to remove the slanderous words "and deservedly so" from my op?
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds