Help! Combofix just stopped dead!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Vallander, Nov 13, 2011.

  1. Vallander

    Vallander Private E-2

    Hi,
    I was following the procedure to run combofix. It installed the recovery console, then began scanning. It said it found a rootkit and needed to reboot the machine, specifically telling me not to do it manually. I said OK and it started but then stopped. It is just hanging with all my icons gone, my machine connected to the internet and my virus protection turned off. What do I do?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It may take some time, I recall one person saying they left the computer, went to bed and by the morning it was rebooted. Choice is yours, wait a while, or reboot the machine yourself.
     
  3. Vallander

    Vallander Private E-2

    Thanks. I was afraid to leave it like that. Sometimes it just hangs on closing down --it's an XP SP3 machine. I held the power button down till it turned off, then turned it back on. Combofix resumed as if it had done it itself. Everything appears to be okay. Pardon my panic, lol.
     
  4. Vallander

    Vallander Private E-2

    Is rootkit gone?

    Hi,
    I ran the READ ME FIRST procedures, MAMB and SAS found nothing, but combofix found a "difficult" rootkit. It tried to remove it, said it needed to reboot my computer but then just hung. (It is an XP SP3 machine and sometimes hangs on shut down. So I held the power button down till it shut off, then started it again. Combofix resumed as if it had done the shut-down, it seemed. I got the log and then ran it again to be sure. It looks like it deleted some of the same stuff the second time. Root Repeal seemed to see a lot. MG Tools ran also. Logs are attached. Can anyone tell me if I still have a problem? The root repeal log looks big, :(
    Thank you for your help. When combofix first hung up, I started a thread for help as I was afraid to do anything. Is there a way to mark that "solved" so that I don't waste anyone's valuable time? Thanks so much-- my paycheck depends on this machine!
     

    Attached Files:

  5. Vallander

    Vallander Private E-2

    Re: Is rootkit gone?

    Well...I was following the "READ ME FIRST" instructions. They never found the rootkit to start with. Combofix, run after them, did. It looked to me like the second run of combofix deleted someof the same files as the first run, which means they returned, so I thought there might still be something there. Also the Root Repeal log seemed long.
     
  6. Vallander

    Vallander Private E-2

    I just realized my mistake--When combofix stalled, I panicked and started this thread because it had specifically said not to manually restart my computer. When no one answered, I gave in and restarted it anyway, and it picked up where it left off. I tried to close this thread by leaving the message that it had resumed and seemed to be okay. I asked how to mark a thread solved, but no one answered, so I couldn't close it. I posted my four logs on another thread--that's why I thought you had them. I'm so sorry! I ran combofix a second time after the stall, so I included that one too. You were being very kind and patient considering how I've botched this request for help!!
     

    Attached Files:

    Last edited: Nov 14, 2011
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Threads have been merged. Please remain in this one now and I will flick through and see what can be edited/deleted to tidy up (post wise)
     
    Last edited: Nov 15, 2011
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    
    :files
    C:\Documents and Settings\Valerie\Application Data\A4451
    C:\Documents and Settings\Valerie\Application Data\FF3pnG5aQ
    C:\Documents and Settings\Valerie\Application Data\fUVelIBtz0c1v
    C:\Documents and Settings\Valerie\Application Data\JpnG5aQJ6W8R9Tw
    C:\Documents and Settings\Valerie\Application Data\NuvS2obF3m5
    C:\Documents and Settings\Valerie\Application Data\Q6dWK8fRZhXjVl
    C:\Documents and Settings\Valerie\Application Data\tPNycA1uv2n4m5W
    C:\Program Files\51FEC
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one and then before running it ensure it's on C:\ NOT the desktop. ;).

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip
     
  9. Vallander

    Vallander Private E-2

    Ok, did the first part -- log is attached.
    Now to embarass myself -- when I go to download MGtools, it offers to save it in the download folder. I that where it goes? If not, exactly where should I put it? (And how do I get it off my desktop?) D'oh!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It should be directly in the root folder of your Windows Boot drive (usually this would mean saved here C:\ ) So if it gets downloaded to downloads folder and you now have it on desktop, right click and select cut, and then go to C:\ and paste it in. :)
     
  11. Vallander

    Vallander Private E-2

    Sorry for the delay-- I had to lend the laptop to my son when his died mid-term paper and am working on a clunky old desktop. I will try to follow your instructions as soon as I get it back. It isn't in a folder now-- I downloaded it directly to the desktop like combofix. :( Is there a way to fix that?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I already explained: ;)
     
  13. Vallander

    Vallander Private E-2

    Just got the laptop back -- disaster! My son said he had to borrow someone else's computer--I don't think he did it. I turned it on and got some message about "XP Security 2012" I think- it happened very fast. Then the icons on my desktop disappeared and the items on the taskbar. There is no "run" window. WHen I tried to run ESET 32 - one of the few remaining items on the taskbar, it froze the scan and shut down the computer. I rebooted in safe mode--no icons. Tried to attach a thumb drive--no way to access it. I'm competely locked out.:cry This is the worst I've ever seen it. WHat the heck do I do now besides get more tissues?
     
  14. Vallander

    Vallander Private E-2

    I got the run window back by changing to the "classic" startup, but I can't get into the control panel or access the thumb drive. When i try to run a program (one of the few I can still see under "programs" it just asks me what program I want to open the file with. No good. Same for the run window. Last known good configuration does nothing. This is terrible!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help?
     
  16. Vallander

    Vallander Private E-2

    Well, I can sort of see the desktop again, but all executable files are ghostly. No executable will work. I went in through the document folder to the download file where I still had the setup files for Malwarebytes. I installed it again in that folder and quickly renamed the exe file "Bam.com". The shortcuts that it added to the desktop and taskbar stopped working and went ghostly, but I was able to launch Malwarebytes and SuperAntiSpyware by this method. Malwarebytes can't find anything else wrong (it may or may not have been tampered with) SAS found two rootkits a couple of trojans and a pile of cookies. Now I can see "my Computer" and my flash drive. So I guess that's progress. Combofix is on my desktop (ghostly) can I rename it something.com and still have it work? Where do I go from here? I also ran TDSSKiller for that particular rootkit but no luck. I am leary of connecting to the internet as I have no active virus protection, but I Combofix, root repeal and MG Tools on my desktop from my last encounter last week--I just can't use them as long as they are named .exe files.
     
    Last edited: Dec 1, 2011
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, rename Combofix.exe carefully to: hb65f.com and try and run it again. Let me know if you were successful. MGTools.exe should be directly in the root folder of your Windows Boot drive (usually this would mean saved here C:\ ) Try renaming that to 7yjhb.com and see if it will run.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is okay to have it on the Desktop as long as the Desktop folder is located on the Windows boot drive. The instructions in the READ & RUN ME stated the below
    However if the user cannot see the Desktop then obviously we would not want it there. And while we prefer C:\MGtools.exe, it could be anywhere on the Windows boot drive. It just makes it more difficult to automate final cleanup steps if it is in an unexpected location. Also it makes it more susceptible to being a suspicious program if not located where we want it to be.
     
  19. Vallander

    Vallander Private E-2

    Well, I renamed Combofix as directed and tried to run it. It warned me that my Eset scanner was active. Suprised, I went in through programs and was allowed to run Eset NOD32. It found one thing Qoobox trojan, which it quarantined. I see the same thing quarantined a couple of weeks ago. However, returning to the desktop, I found that my renamed combofix had disappeared, as had my renamed MalwareBytes. I renamed and ran MGTools, which then suffered the same fate. I still had a copy of renamed malwarebytes in my download folder, which can't find anything (and seems to complete awfully fast...) A task bar icon for SuperAntiSpyware reappeared --this finds something called "system.brokenfileassociation" and quarantines and removes it--but it just comes immediately back. Can I save a copy of Combofix to my flash drive somehow? It looks like my installer is ghostly too though... I just found the renamed combofix file in the windows/prefetch folder, now it's named hb65f.com-08157917.pf
     
    Last edited: Dec 2, 2011
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So why did you then start to run Nod32 instead? What happened when you tried to run Combofix? It gave you the warning about ESET nod32 and then what? Did it just close itself down?
    Qoobox is not a trojan. It is the back up folder of things that Combofix deletes.
     
  21. Vallander

    Vallander Private E-2

    Then I messed it up worse. Combofix stopped loading and had a dire warning that there was an active scanner running and it was dangerous to run that way. So I discovered that I could now get eset NOD32 to run, so I ran the scanner from there, thinking I'd do that first while I had access, then shut it down. When I went back to combofix, it was gone. Look, I know I'm a head smacking nube when it comes to this stuff, but I really do appreciate your help and I really am trying. I was just afraid to run combofix under those circumstances. It also said something about running a "limited" scan because it was more than a month old (barely. I tried unsuccessfully to uninstall it), so I thought THe NOD32 might be able to catch this. D'oh!
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download a fresh copy of Combofix, let it overwrite the old, and try and run it again despite the warning about NOD32 running.
     
  23. Vallander

    Vallander Private E-2

    Okay, finally got the file associations fixed so I could run .exe programs.
    Downloaded Combofix and others--logs attached. MG Tools gave error:
    c:\windows\system32\cmd.exe
    c:\PROGRA~\Symantec\S32EVNT1.dll
    An instalable virtual device driver failed Dll initialization.

    I told it to ignore that and proceed.

    After everything else I ran Eset NOD32 and it found but was unable to clean this:
    Winlogon.exe(1360) - a variant of Win32/Dorkbot.B worm

    There is a new folder in my C: folder caller RECYCLER. The same folder appears on my flash drive, which I assume is how this computer was infected. (I think this means the other computer in the house that is slowing down is infected also, but one thing at a time.) This was not visible to Eset before all these other
    scans ran.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 27 <--- Uninstall outdated Java.

    What is this?
    C:\Dc1.zip

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Valerie\Application Data\Miriru.exe
    C:\Documents and Settings\Valerie\Local Settings\Application Data\5d2f002jlbk
    C:\Documents and Settings\All Users\Application Data\5d2f002jlbk
    C:\Documents and Settings\Valerie\Application Data\50B9.exe
    C:\Documents and Settings\Valerie\Application Data\50BF.exe
    C:\Documents and Settings\Valerie\Templates\5d2f002jlbk
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Miriru"=-
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Download this tool and run it with the flash drive connected to the computer:
    Panda USB Vaccine. Let me know what happens.


    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  25. Vallander

    Vallander Private E-2

    Didn't work. I followed your instructions and it looked okay for a while, then the RECYCLER folder reappeared. I ran combofix again because I hadn't run MGTools yet, and I thought I might catch it before it reappeared. No luck. Logs are attached.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What didn't work?

    The RECYCLER folder is part of Windows. It is the Recycle Bin. If you have been trying to delete this folder, you need to stop doing that.

    Are you having any malware problems?
     
  27. Vallander

    Vallander Private E-2

    Really? Sorry, I was going by a previous post from this past September, where someone described it first as the RECYCLER virus, then said that Microsoft Security Essentials had identified it as win32/Dorkbot, (http://forums.majorgeeks.com/showthread.php?t=244260&page=2)
    Since I was having similar problems and the RECYCLER folder appeared on both my DataTraveler flash drive and my infected laptop, and since my laptop's Eset program identified a threat that it couldn't clean as Win32/dorkbot.B, I assumed they were connected.
    The RECYCLER folder does NOT appear the desk top computer I am typing this on, (I have it set to show hidden files), which is also a Core2Duo with virtually the same software, or my daughter's laptop, which is almost identical to my infected one, so I figured the RECYCLER folder was from the virus.
    The Eset Threat Encyclopedia (http://www.eset.eu/encyclopaedia/win32-dorkbot-b-worm-ngrbot-gqj-w32-kolab-gen-p) says that the worm creates a RECYCLER folder to hide in--it said a lot more than that but I won't pretend I understood it!) So I thought this RECYCLER folder was evidence of continued infection. Also, a couple of my desktop icons (root repeal and a folder of tools) are...dark-they don't look normal. I guess that could be something else. Sorry--I'm not very good at this stuff!
    To answer Kestral13! -- I have no idea what Dc1.zip is--it isn't showing on the computer or in a search for that file. Where do the logs say it is?
     
    Last edited: Dec 5, 2011
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was exactly where I said it was: C:\dc1.zip

    It isn't showing in the logs though any longer.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  29. Vallander

    Vallander Private E-2

    I'm sorry, I did look in the C: folder but dc1.zip was not visible. I searched for it too but nothing came up. Apparently all my "superhidden" files became visible though, so the RECYCLER folder had this in it: S-1-5-21-1896466947-3091375771-3867100828, which disappeared when I hid the "superhidden" system files, so I guess not a virus?
    I followed all your finishing procedures and other than one small detail, all seems well. (There is a folder on my desktop which has had it's status changed from visible to hidden, as have all the files it contains. It has some set-up files and shortcuts etc.)
    Thank you SO much for your help and for putting up with my ineptitude! You guys are heroes! I looked to see if there was a place to help support the site, but I couldn't find one? Is there a way to mark this thread as solved (ANOTHER victory!) or do you do that? Thanks again!
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening. There is indeed a way to show your gratitude, if you take a look at the link at the end of all my posts. (Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies)

    No need, we do not close threads as a general rule. :)You are *most* welcome for the assistance from us.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds