combofix problems?

Discussion in 'Malware Help (A Specialist Will Reply)' started by jmdt, May 19, 2008.

  1. jmdt

    jmdt Private E-2

    After mcafee found a file infected with pws-banker, and I started to notice a couple of password problems (e.g., one email account won't work with the password) I came here and started following the directions to clean my computer. While following the directions on the link below:

    http://forums.majorgeeks.com/showthread.php?t=139313

    I found that I seem to have problems running combofix. I am able to put the correct information into the run prompt, but then it goes to a blue screen and seems to do nothing else. I have noticed that it does change the time to a 24 hour clock - but it does not seem to be running and after having it "run" for over 4 hours there does not seem to be any progress. Suggestions?

    Using the programs before this in the directions (SUPERAntiSpyware, SpyBot - Search & Destroy, and Malwarebytes Anti-Malware), I have found no problems so far . . .
     
  2. jmdt

    jmdt Private E-2

    While waiting for a response, I also went ahead and ran MGtools. I am attaching MGLogs.zip to this.

    Thank you for any help you can provide on this!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing much in the way of problems......

    You can use windows explorer to find and delete:
    C:\log26.log
    C:\log26.tmp
    C:\log59.log
    C:\log59.tmp
    C:\loga.log
    C:\loga.tmp
    C:\logb8.log
    C:\logb8.tmp
    C:\loge2.log
    C:\loge2.tmp
    C:\WINDOWS\unins000.dat
    C:\WINDOWS\unins000.exe

    Then delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Also use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5

    Then reboot and install:
    Java Runtime 6

    Now tell me what problems / issues you are having.
     
  4. jmdt

    jmdt Private E-2

    Thanks for your prompt response Tim!

    My computer has been running slowly but I didn't notice anything particularly wrong until mcafee found a file in my temp folder infected with psw-banker.

    So I have three questions.

    1) Given the clean scans I have had, should I be concerned about psw-banker anymore? As an update, I'm running the mcafee freescan right now and I have found 4 problems so far - 3 are combofix-related (of the remadm-proclaunch/171 variety) and 1 psw-banker (it's in C:\quarantine\ and it is called TFR1D6.tmp.Vir). How should I proceed with this?

    2) I was originally concerned because my work email kept logging all of my attempts to login as wrong password/wrong username even when it was not. I initially thought it was my work server until I had problems with my yahoo password. I have since found out that the work server is down (which explains the work email problems) and I think the yahoo error might simply be a glitch. How will I know my computer is clean?

    3) I'm going to follow the guides on MG for how to clean up a slow computer - aside from that, any other suggestions?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    where are the combofix-related files? the psw-banker is in quarantine ...so it is not a problem.

    You may wish to post in the software section regarding speeding up your computer...You may wish to use a Startup Manager
     
  6. jmdt

    jmdt Private E-2

    c:\cf\psexec.cfexe
    c:\CFix\psexec.cfexe
    c:\documents and settings\...\desktop\CFix.exe

    Thank you for the speed suggestions - I'll try it after resolving this issue.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are combofix files....not malware....we will remove them now:
    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  8. jmdt

    jmdt Private E-2

    Hi Tim,

    I've followed the steps you have provided and I am in the process of installing Java 6 and the startup manager. Everything seems to look good at this point. I will follow your suggestions with speed momentarily. Should I be concerned about the psw-banker anymore at this point? Will I need to change all of my passwords?

    Jane
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need not worry about the psw-banker.....and it is always a good idea to change passwords after an infection!

    Good luck and safe surfing. :)
     
  10. jmdt

    jmdt Private E-2

    Excellent. Thank you for your wonderful help Tim. It is much appreciated!

    Jane
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome. :major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds