Need help asap-combofix wiped me out just now

Discussion in 'Malware Help (A Specialist Will Reply)' started by AlphaPup, Jan 24, 2010.

  1. AlphaPup

    AlphaPup Private E-2

    OK-previous forum I had problem with auto disabling.Did it.then I downloaded Combofix (from bleepingcomputer site).Ran it.Well,message came up I do not have Microsoft recovery installed!Hello!!!what have I been saving the restore point to????asked if I wanted to install..checked NO.Then Box came up:Application wants to scan "catchme.tmp".Said No,then same message with IE..again,No.Then blue screen with Combofix ran:about line 32,message came up:IE must disconnect-saw it said PEV.exe problem (in C/ documents in temp file).Combo still ran(didnot send).Well,see below.It cleaned me out.It rebooted,on the desktop-have no programs in system,all files are gone.EVERYTHING removed except recycle bin,IE and I can,obviously,see my Cable moden connections.Do I crash completely and redo everything with disks I have? Should I wipe out completely??What do I do?Did I get a corrupted Combofix??did the autorun disable 'incite'this deletion? Grandma is whizzed off and looking at a blue screen startup with NADA installed.Need help,guys-asap : (((((((((( I ran ComboFix 'cause everyone loves it and said we should have it.I got it alright : :)cry
     

    Attached Files:

    Last edited by a moderator: Jan 24, 2010
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we have found there is a recent bug in ComboFix that has just started causing this problem.


    Get the C:\QooBox\ComboFix-quarantined-files.txt and attach it here so we can attempt to work up a fix to restore everything. We will need to use ComboFix to restore everything so we will have to restore it to since this bug has deleted ComboFix.exe from the Desktop too (or from whereever it was run).
     
  3. AlphaPup

    AlphaPup Private E-2

    add this info:I FOUND everything thru back door.It is there.EXCEPT:ran Malwarebytes-FOUND viruses-BUT!!computer drive BLEEPED-computer shut off!!Just rebooted-running scan again to see if I can find the infection.I knew it as soon as the darn Combofix started.I was going to flip off the 'puter.Next tuime,will listen to myself!LOL Do you think I should just crash and reboot with discs all over?? Here are files:
     

    Attached Files:

    Last edited by a moderator: Jan 24, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see this thread if running XP:

    Combo deleted everything..

    Do not attempt to restore anything on your own. Make no more changes to your PC. Just get us the De-Quarantine file so we can make a fix. Also get the ComboFix.exe file out of the Quarantine and back onto your Desktop.
     
    Last edited: Jan 24, 2010
  5. AlphaPup

    AlphaPup Private E-2

    I Read the other replies:I do not have the icon on desktop.I was able to manually restore some of my files to desktop.Right now I am searching for the Combo.exe file to send to desktop.Or??? I have one file: SetPath.Bat
    FYI-have most of my files corrupted.BleachBit had hidden attachment to stop a lot of scans,removals etc.Ditto for Malwarebytes.I am just crashing the entire computer and starting over.The "problem"is deeper than one thinks,I believe.I am seeing blocks,added attachments for "unknown",redir,key registry alteration.I do not think that this is a "simple"fix.Dumb as I am,I will listen to my gut and crash.Thanks!!Sincerely appreciate your rapid response to this problem.One thing I found discerning (my reason to crash)Malwarebytes crashed when viruses were found and computer closed,rebooted!Upon second rescan-NOTHING!no virus.THEN,I opened all mbam files etc.There were new hidden attachments added at the EXACT TIME Combofix crashed..exe files,others were deeply altered.Hope this little bit assists.Off to crash and Burn now.THANK YOU ALL SO MUCH!!Grandma
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't post anymore inline logs. All logs need to be attached. If too large to attach, ZIP them and attach the ZIP.

    I repeat!!! Don't do anything on your own. Only do what we request.

    The ComboFix file is here:

    C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Desktop\ComboFix.exe.vir


    You need to copy the ComboFix.exe.vir file back to your Desktop and leave off the extra .vir extenstion. Thus when done properly, you will have the below.

    C:\Documents and Settings\Owner\Desktop\ComboFix.exe

    If you don't know how to copy the file then tell us an we will give you something to run.
     
  7. AlphaPup

    AlphaPup Private E-2

    BTW-just reread the quarantine.How did autorun "restart"when it was disabled??Saw file running in D/ autorun.
    One quick question?when I redo entire computer:is this combox fix corruption still there?do I need to wait before I crash and re do??
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stop posting unnecessary messages and do what was already requested.
     
  9. AlphaPup

    AlphaPup Private E-2

    I know-apologies.I am in my 60's and real tired.I try.I attached the unknown files for you.I HAVE NO combofix.exe.cANNOT UPLOAD TO YOU:
    Upload Errors
    COMBOFIX.EXE-301D4E7B.pf:
    Invalid File
    COMBOFIX-DOWNLOAD.CFXXE-2BE3D9AE.pf:
    Invalid File

    ONLY 2 files I have outside of the txt,pdf and bat files.I have over 100 corrupted files in the prefetch.OK-will shut up now and wait.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not want you to upload anything here. My instructions said to copy the below file

    C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Desktop\ComboFix.exe.vir

    back into your Desktop folder and also rename it so that it is named ComboFix.exe

    Do you not know how to do this?
     
  11. AlphaPup

    AlphaPup Private E-2

    ok-you better tell me what to do.I am very afraid I will do it wrong.SO SORRY.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To copy ComboFix from quarantine back to desktop, click Start > Run > copy paste the below into the run box and then click OK.
    You should now have a ComboFix icon back on your desktop. Tell me if you see this now. We need to do this before we can attempt to restore the files.
     
  13. AlphaPup

    AlphaPup Private E-2

    followed exactly.I do not have the icon.I have only the Combofix.exe showing on desktop
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but when the file is there the icon shows as a red circle with a white tiger in it and I assume that is what you see?
     
  15. AlphaPup

    AlphaPup Private E-2

    OK-it JUST came up on the desktop-the ICON now appears where the combofix.exe "box" was.My computer is slowing and hanging now.I really am sorry.But I am a gnat in you "guys" expertise!Blessings for bearing with me.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Some people live on computers and some do not. ;)

    NOTE: This fix only applies to this user! It will definitely not work for anyone running Vista or Win 7 so do not attempt to use this fix
    if you are not the user who created this thread.



    Now we need to use ComboFix to restore files. This will only restore, it will not delete anything.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run
      properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad ( Click Start > Run, type notepad then press Enter ) and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, tell us how things are looking. You should check each user account.
     
  17. AlphaPup

    AlphaPup Private E-2

    I am printing out all instructions.When I am completed I shall return to this post with followup.I will be gone at least 1 hour.Have to give meds to my rescue dogs.<sigh>tough getting old.You are a person of professional abilities to the nth degree,patient,understanding.You may be a MajorGeek,but you are also one hell of a Major person! Be Proud! SALUTE,BABY! See you later.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thank you! Take care of what you need to do and then come back to finish this off.

    Make sure that you use notepad to create the CFScript.txt file. Do not use Wordpad. Also make sure that you use copy & paste to get the information correct.
     
  19. AlphaPup

    AlphaPup Private E-2

    <sigh>No Luck..did exactly what was written.Did click,Start>run,typed notepad.Then the untitled new notepad box came up.Did cut/paste.Saved as CFscript.txt in Ansi on desktop.No Icon.Just txt 'blue notepad icon'. what did I do wrong?what does the CFscript Icon supposed to look like?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should look like this CFscript.jpg

    Do you see both it and the ComboFix icon?
    Did you drag the CFscript.txt icon ontop of the ComboFix icon?
     
  21. AlphaPup

    AlphaPup Private E-2

    Oh,God,It does<head is bowed in shame>.I was looking for some fancy little picture in a box.Will do now.Give me a few to return.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just be patient while it runs. Depending on how much there is to copy back, it can take awhile. As it runs, you will slowly notice things reappearing on your Desktop. Don't do anything else during this time. You not even be here with your browser. During the time you are running ComboFix, your browsers should be closed.
     
  23. AlphaPup

    AlphaPup Private E-2

    :clap you guys rock! I am only user on this computer.So,no other accounts.ALL BACK,esp my beloved HJT and my MAJORGEEKS link :heart!!!!
    I ran F8 both Admin/owner.Only items amiss:(6)redir were back for microsoft,But HijackThis easily removed AND in the privacy folders-MAJORGEEKS was blocked,along with bleeping computers,and all the https sites I had!Easy change.Lightening fast fix you gave.THANK YOU.What can I do now??
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also will have an issue with Desktop.ini popping up in a notepad Window at reboot. To fix this, do the below.

    Navigate to the below file with Windows Explorer:

    C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini

    Then right click on it and check the Hidden attribute. Then click Apply and OK.

    Do the same for the below file:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini


    See if it still occurs at reboot.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal! You should not be using HijackThis on your own. You are deleting things that are normal. Uninstall HJT and don't use it unless an expert instructs you on how to use it.
     
  26. AlphaPup

    AlphaPup Private E-2

    well,just ran search for both files.came up in seconds-dropped open property box and hide.Rebooted.No problems.Thank you.Um,like in a "forum"someone said to check all the redirect links from microsoft.It was just re-routing for marketing purposes.They were 'harmless'files.Believe me when I say I learned the hard way from HJT.After some crashes,I began education quickly.You see,I am a firm believer in privacy,freedom (am old hippy leftover ).Microsoft?Their marketing tactics are annoying.For instance,right here on MajorGeeks?scrolling down over the greenhighlighted areas?Bing comes up with pop up for their products.And my pop up blocking is med-hi! Any computer 'tool'must be used with discretion and knowledge.In 2 instances of "forum" and both times I needed help after following "what to download" and warning on what to "delete".Seriously?who ever anticipated a 'messed-up' Combofix?It happens.But I learned alot from this nasty experience.It will not happen again.I will not be running ComboFix.It fixed me too well!You may get me once,but not twice!THANK YOU THANK YOU.EVERYONE on Forum is Special and Helpful.And,yes,the MajorGeeks admin certainly rock.
    ps uninstall HJT?RFLMAO..that sucker saved me many a time!!
    GOOD NIGHT!GOD BLESS!remember:computers are tools,not your precious life!enjoy downtime!They break,fix them.You mess up?fix yourself!Hugs to some of the best people on the planet are right here on this forum!!!Grandma:dood
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to lines like the below
    Note: Run on sentences and paragraphs are a no no!! We will not read them since they take too much time to figure out what the point is. Also we will only discuss malware problems in this forum. Too busy to do otherwise. :)

    You may find that some day, it could be the only way to fix your problems. ;)

    Are you currently having any malware problems?
     
  28. AlphaPup

    AlphaPup Private E-2

    I know this will whizz you off.Everything was quite fine after I followed your instructions.To the letter.Having said that?Removal of Combofix from the computer was a new experience.It cannot be removed.In addition,my pic files had the .vir still in there.AFTER the fix.My Photo Explosion was gone from the Desktop.Try and remove Combofix.What else besides the F8 can one do to remove?The .exe files showed.The properties were all blanked out.Unable to remove.That was in F8 admin.I may not be a professional programmer,but I do utilize syllogistic reasoning and Venn logic in decision making.Blame my "setting" for non-allowance of removal?Not logical.Other files affiliated with said problem were removed.Nothing else BUT Combofix was removed.Everything had to be directly verifiable correlated to said program.Your extended Help was/is deeply appreciated.Understand this,not one single fix/programmer/human is infallible.One will never truly understand why it works for one person and not another.Different extrapolating factors,variables etc are never quite analyzed.We use general statistics only.I know you hate reading run-on in what you consider non-germane to the issue.I believe it is!This Combofix issue is not cut and dry for starters.Critique:most programmers think issues are resolved when the medium Bell Curve is achieved.No.The people/issues with variables who fall either flat or peaked out are the ones ignored. Philosophy,statistics,programming et al are one unique blend.Like life,there is always the questioning 'oddball'.I am one of them.When things "do not compute',people like me must be there to question!And,you:major are the ones I seek answers from.Bless you for being there.Grandma(who will not die and go away!)BTW:I do not wish to overextend the kindness and generosity of your expertise.Remember this:my computer was tippy top before I downloaded the Combofix.It is irrelevant and ignorant to blame anyone.Like blaming a particular for Google 'issues'.Failure is inherent,especially in this day and age of mass computers.We only fail when we stop trying.I know I just made you :mad.I wrote this because I do CARE!I hope people read it and think.I have exploited your forum for philosophical gain to all!Not so bad considering what others do.Amen,Major! Enjoy.You and the others are precious few individuals that society needs.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you mist the below in my previous message?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the you have .vir externsions on restored files then you did not follow my instructions properly. This would mean you manually copied files back and did not remove the .vir extension.

    If you truly Uninstalled ComboFix with its uninstall command or otherwise have deleted the QooBox folder then your system cannot be fixed. If you still have the Qoobox folder with the incorrectly remove files in it and you have not removed any of the files from it yourself, the below procedure and new tool will automatically fix it and permissions problems.

    Download the new fixed version of combofix.exe and save it to your Desktop. DO NOT RUN IT YET!!! Just make sure you have the new version downloaded and saved.

    Now download this file > http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe


    You should be able to run it from any location but save it to your Desktop if possible. As long as Qoobox has not been tampered with, the tool shall be able to automatically do the below.
    • restore all the required files/folders
    • restore the perms
    • set the correct attributes for desktop.ini
    Now run the CFDQ-UsrPrf.exe program by double clicking on it.
    • Immediately after you run it, YOU MUST NOT reboot your PC. Don't do anything else but continue on with the below..
    • Now immediately run the new version of ComboFix that you saved to your Desktop earlier. This should cause a reboot of your PC after running if malware was detected and removed.
    • After reboot attach the C:\combofix.txt log.
    • Also please run the MGtools.exe program as specified here:Using MGtools Then attach the requesetd C:\MGlogs.zip file
    • (See: HOW TO: Attach Items To Your Post )
    Now tell us how things are working.
    • Do things seem to have been restored?
    • What malware problems are you having?
     
  31. AlphaPup

    AlphaPup Private E-2

    Yep! I "mist"it.I am in a fog.But,my dear,you read it.You know I appreciate you : )

    I crashed,redid the entire computer!My ocd kicked in.I did follow what you said to do!Honest! I am a-ok now.Running tip-top.Passed all the recommended online tests:No open ports,No hidden files,etc.No recommendations for me.I am real (ethically firm)about privacy!

    ChasLang-YOU DA BEST!! And all the other forum people!:dancer
    YOU ROCK!YOU REALLY HELP.Hands Down.

    for now,no Combofix for me.BUT-MAYBE!!I never close the door if a MAJORGEEKS says so!;)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds