Combofix, MGtools both hang?

Discussion in 'Malware Help (A Specialist Will Reply)' started by t3d, Dec 13, 2010.

  1. t3d

    t3d Private E-2

    Hi,

    Hoping for a little help.....

    I've read through and carried out all the preparatory info on checks to carry out before posting.

    First evidence I saw that something was amiss with this machine was an inability to run spybot, which I could get around by renaming to "spybot1" or whatever. Also suffered intermittent browser redirects.


    Once I'd got it to actually open, running spybot alone didn't seem to solve the problem. However now I've installed and run the other progs suggested in your xp cleaning procedure, a few nasties were flagged up and now it seems like the symptoms are gone.

    BUT, neither combofix or MGtools will run,so I'm concerned there may still be something lurking.....
    I've attached my logs, including one from TDSSkiller, which also found stuff.

    Would very much appreciate some expert opinion!

    Thanks in advance
     

    Attached Files:

  2. t3d

    t3d Private E-2

    ....and finally:
    TDSSkiller log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    TDSSKiller has solved your main problem, however your MGlogs.zip is incomplete, and I would like to see a full set of logs from it.

    Please do this, click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window, enter the below commands each followed by the enter key. Note there is a space after the cd

     
  4. t3d

    t3d Private E-2

    Hi and thanks very much for the quick reply...


    OK, running it via the cmd prompt resulted in the same outcome, as far as I can tell.

    It gets as far as
    "NOTE: Ignore any messages about not finding registry keys!......" etc,

    then there's about 10 seconds activity from the HDD and then everything goes quiet.

    Program then seems to have hung, can't get any response out of Windows, only answer is a hard reset.

    Cheers!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay lets try this:


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Now check C:\MGlogs.zip. Double click to open it, are there two logs in there? If so attach the whole C:\Mglogs.zip, if not move onto this step:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. t3d

    t3d Private E-2

    OK,

    "ShowNew" appeared to run to completion without any error messages (There were messages but nothing that suggested an error, so as you asked only for details of error messages I didn't go to the trouble of typing them out)

    GetRunKey ended up with the same result as before, it got as far as the message about "ignore any messages about not finding..." followed by a period of inactivity, then the computer hung.


    I've attached the two logs from OTL..


    Thanks!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is inside of this folder?

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    At this point I would like for you to rename combofix.exe to greenfinch.com and attempt to run it again.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. t3d

    t3d Private E-2

    C:\Documents and Settings\All Users\Application Data\AEz6IITDk contains a file called "PCGWIN32.LI5"

    I hope that means more to you than it does to me! :-D


    Have attached the OTL report - 12142010_153617.log


    Combofix still wouldn't run without problems. Same issue as the first time I ran it - it gets to the message the ends "...may easily double" and then nothing, even if left for ages - hard reset required.

    With MGtools, things were a little different this time. As you'll see, some more files were created in the MGlogs archive than the first attempt, but it still outwardly behaved just as before, hanging and requiring a reboot after the message about registry keys.

    Now I'm wondering if I should have left it for longer before considering it "hung"! But it was probably half an hour or more.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\All Users\Application Data\AEz6IITDk <--- You can just delete it.

    Run OTL again as you did in my post # 5 and attach the log.
     
  10. t3d

    t3d Private E-2

    File deleted, OTL log attached.

    Any ideas what program that file was associated with?


    Thanks for your quick responses!
     

    Attached Files:

    • OTL.Txt
      File size:
      25.7 KB
      Views:
      2
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was just junk I believe.

    Now, what problems remain, if any?
     
  12. t3d

    t3d Private E-2

    OK, well it's deleted.


    I'd cautiously say there were no obvious problems now, but this is really the same situation as when I first posted - no apparent issue with opening spybot any more but just the concern that neither combofix or MGtools would run without hanging....


    Thanks!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is most likely due to your PC specs. Not sure what the processor speed is but your PC cannot properly run Windows and other applications as it does not have sufficient memory. You may have needed to wait a lot longer. Your OTL log showed the below
    You need to have a MINIMUM of four times as much memory ( 4 x 256 Mb = 1 Gb ) but we highly recommend 8 times ( 8 x 256 = 2 Gb ) if you wish to have proper performance.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. t3d

    t3d Private E-2

    Thanks guys,

    Chaslang: nope, the specs aren't great on this machine! It's a ten+ year-old HP laptop, I think it was originally shipped with Windows 2000, but now running XP.

    The processor's a PIII 650MHz, with, as you observed, 256MB of RAM. I don't think these machines were ever supplied with anything more than 128MB of RAM as standard, expandable to 512! So I guess I could double the RAM.... On the face of it XP runs pretty satisfactorily as it is. It struggled with Spybot and AVG9 - the TeaTimer and AVG both slowed down the boot to well beyond acceptable limits, so I ditched them.
    I'm not expecting blistering performance from this laptop, just reliability.

    Anyway, since running all the checks from your cleaning procedure, even with the combofix and MG tools issues, everything seems to be working crisply.

    OH, there is one last issue - there are folders on the C drive called "ComboFix1" and "greenfinch" (a leftover from when Kestrel13! had me rename combofix in an attempt to get it to run).

    Although they're listed as "folders", they have the "my computer" icon. Presumably because these are renamed, the normal ComboFix uninstall didn't remove them.... how do I do it manually???


    I've been through all the final checks and toggled systm restore - thanks very much to both you and Kestrel13!, keep up the good work guys!
    Cheers
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my opinion, not worth the money as it is not enough memory anymore. But if you are happy with how slow it is ( and it will get slower as all software keeps updating ) then it's your choice if you want to at least upgrade to that amount. Should be relatively inexpensive since 512MB is next to nothing these days.;)

    Great! :)

    Just delete them. MGclean.bat will cleanup most of what we put on but only with the normal default names and folders. Anything not using the defaults names will not be found and removed automatically. The same is true for the ComboFix uninstall itself. It will only find the properly named files and folders.

    You're welcome. Surf safely.
     
  17. t3d

    t3d Private E-2

    Yeah, we'll see how it goes. For the moment things are working fine but I'll keep an eye on the performance as progs are updated. This is a seriously "budget" (or if you prefer "worthless"!) machine, so I may see if I can pick up some RAM on the cheap on Ebay etc., to double mine to an eye-watering 512MB!

    There's actually never going to be a lot of software on this machine anyway - I originally unearthed it as a cheap tool for hooking up to vehicle diagnostics software so it's not like it's ever going to be running the latest games, predicting the weather or some other intensive job!

    Thanks again for the guidance.


    Cheers
    T
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds