ComboFix Deletion (Quarantine?) of User Files

Discussion in 'Malware Help (A Specialist Will Reply)' started by braskys_scotch, Apr 25, 2014.

  1. braskys_scotch

    braskys_scotch Private E-2

    Hello all,
    I've seen a few threads about ComboFix sweeping out User files and I'm now adding my name to that list. I took my laptop to a technician; he ran ComboFix; this happened.
    I'm running Win7x64 and had originally taken in the laptop due to frequent shutdowns that were preceded by an IAStorIcon.exe error that would just turn my computer off randomly.

    I'm attaching the log file here. Thanks in advance for any advice/assistance!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What problems are you having? If you just want to restore those files, you should post in the software forum.
     
  3. braskys_scotch

    braskys_scotch Private E-2

    It may just be a simple restore from the quarantine. Based on some other ComboFix-related threads/posts I saw (and not knowing much about this), I started here.

    Is there any reason why this happened, i.e., are there considerations before simply restoring the user files? I didn't perform the ComboFix scan and know little about it or why this happened.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :) You attached a log in the .rar format. I would like to see a proper .txt (text file) from combofix. It should be on the root of the drive that you boot from. Eg: C:\DeQuarantine.txt Attach that for TimW and he will be able to help you.
     
  5. braskys_scotch

    braskys_scotch Private E-2

    Thanks! Please see attached zip file.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That is not the log that was asked for.
     
  7. braskys_scotch

    braskys_scotch Private E-2

    Sorry. I did not see any file named "Dequarantine." That file is the only one in the C drive folder from the day this all happened with the log from when ComboFix was run.

    Is there something in the Qoobox folder that I should look for? Apologies for not having the strongest grasp of this stuff.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise. You will have a dequarantine.txt soon. ;) I worded it wrong. I have a fix for you but it is unfortunate that it's too large for the forum to handle inline. I have zipped up a script for you. So follow these instructions.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste all of the text in the below attached text file. (CFScript.txt) (You will need to unzip CFScript.zip first!) Ensure you scroll down to select ALL the lines:







    • Save the CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. You should now have a C:\Dequarantine.txt file to attach for me.
     

    Attached Files:

  9. braskys_scotch

    braskys_scotch Private E-2

    Just to confirm before doing anything, I just downloaded ComboFix.exe from bleepingcomputer. There was no other version of ComboFix left on my computer, and the entire problem started when a computer tech ran ComboFix, so there was no READ & RUN ME involved on my part. I only bring this up because I want to be sure whatever I do is best practice under your/TimW/et al's advisement.

    If performing the instructions with the file I downloaded from bleepingcomputer is fine, then I'll go ahead and carry out the steps later tonight. Please confirm at your convenience and many thanks for your input.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. braskys_scotch

    braskys_scotch Private E-2

    I was able to run ComboFix through completion. The ComboFix.txt log that resulted is attached here. Am I supposed to see the DeQuarantine file yet?

    Thank you again.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The dequarantine.txt should be on the root of the drive you boot from.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am just questioning something about how we go about this in the background. It's been such a long time since I've had to restore files which CF killed. Hang in there. :)
     
  14. braskys_scotch

    braskys_scotch Private E-2

    Hi,
    I searched for any file named "dequarantine" and have had no luck. Totally understandable if this is as frustrating on your end as it is mine.

    I can see the User files with all the .vir extensions (C:\Qoobox\Quarantine\C\Users...), so I don't know if it's just a matter of renaming and moving files and User folders.

    Thanks again for all the help. Let me know if there's any clarity that I can provide regarding the issue.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said please hang in there. I will get back to you asap.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to attach a file n: C:\QooBox\ComboFix-quarantined-files.txt Please do this braskys_scotch. :)
     
    Last edited by a moderator: May 1, 2014
  17. braskys_scotch

    braskys_scotch Private E-2

    This file is blank. Is there possibly a misstep or does this signal that anything else needs to be done? Thanks!
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think the "tech" you took your machine to has alot to answer for. He kept an outdated copy of Combofix and it's instability combined with the tech running it at that point is what wiped all those files. That file should be there, but who knows... the tech may have removed it.

    I have a fix that will hopefully implememt; almost all worked up for you already. I am just running short of time this morning, and must return to you a little later on. :)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Same way as I laid out instructions for in my post #8 you need to do the same with this script that I have attached (as a zipped file - CFScript.txt inside of CFScript.zip)

    After doing that you should now actually have a C:\Dequarantine.txt file to attach for us.
     

    Attached Files:

  20. braskys_scotch

    braskys_scotch Private E-2

    Hello, I still unfortunately had the same results: no Dequarantine.txt file anywhere; just the C:\ComboFix.txt file, which I'll attach here. I'm also including an Add-Remove Programs.tx log txt file also produced from the ComboFix output. Additionally, there is a txt file produced named ComboFix-quarantined-files.txt, but it is totally clear (O KB). Any insight why no Dequarantine.txt file is produced upon completion of the ComboFix program cycle?

    As always, thank you for your help and guidance!
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have ANY of your files been restored? :confused
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried a system restore to before you had the "tech" work on it?
     
  23. braskys_scotch

    braskys_scotch Private E-2

    Meaning restored to their original location under User\My Documents, etc.? No. The files are all still under C:\Qoobox\Quarantine\C\Users with the .vir file name endings. If this prompts any thoughts or questions, please let me know.

    I want to again fully acknowledge I'm not adept at dealing with any kind of malware issue and have limited computer familiarity compared to many of the posters here. Please feel free to ask any questions that may help resolve this issue and don't consider any to be "too dumbed down" at this point.

    Thanks again.
     
  24. braskys_scotch

    braskys_scotch Private E-2

    I had not tried a system restore before taking it in - still under extended warranty so hadn't thought much of it.

    Previously, it had been shutting down after an IAStorIcon.exe error would pop up. When the tech said he was going to run ComboFix I didn't know what it was and presumed he knew what he was doing.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hang in there and hold off on the system restore. Trying to rework a fix up for you. My last was ineffective due to an error.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\Users
    QUIT::
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
    • Do you now have a C:\Dequarantine.txt?
    • Has anything been restored?
    • This is just a test that may or may not fix everything that I wanted to try. If it is successful please be aware that all the nasties will have been restored too, but we can deal with that afterwards.
     
  27. braskys_scotch

    braskys_scotch Private E-2

    Hello. I followed the instructions below and copied/pasted the text for the CFScript.txt file, but ComboFix has not moved beyond the initial blue screen, "Scanning for infected files ... This typically doesn't take more than 10 minutes. However, scan times for badly infected machines may easily double."
    It hasn't quite been an hour, but shouldn't it take less time to move beyond this first screen?
     
  28. braskys_scotch

    braskys_scotch Private E-2

    Thank you! The files are restored, and a DeQuarantine.txt file was produced. I'd like to attach it here for you, but the file attachment feature does not seem to be functioning in this reply.
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  30. braskys_scotch

    braskys_scotch Private E-2

    Hi. The DeQuarantine.txt file is 17.1MB. Is there a compression program that will reduce it to the size that allows for attaching it here? I can download a compression program and try attaching it from my work computer (I have it saved on google drive).

    I tried zipping it last night, and the compression programs (7zip, WinRAR) kept denying me authorization to do so. Also, I couldn't select the attachment feature (as though it was a dead link) in my reply in chrome though I could do so in firefox. This continued even after rebooting. I'm not sure if these items are relevant, but you all know significantly more than me so I figured I'd mention it.

    Thanks again.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The built in windows compression should work just fine, right click and send to compressed zipped folder. Also, any third party software should work too. However the limitations of this forum is 2.00MB for a zipped so you could split it into seperate parts, or........ use mediafire.com (we obviously don't do this usually, but this would be an exception)

    Have a look here also c:\qoobox\quarantine ... does anything remain in that folder?
     
  32. braskys_scotch

    braskys_scotch Private E-2

    I will check the c:\qoobox folder when I return home late tonight. I was able to attach the DeQuarantine.zip folder here at work. I appreciate the advice on handling that. Looking ahead, is there anything we can glean from the DeQuarantine.txt file or c:\qoobox folder, or will we primarily be looking for results with the READ & RUN ME FIRST Malware Removal Guide?

    Thanks again!
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes it's extremely important that you follow our malware removal procedures now at this point. Attach all of the requested logs as soon as you are ready. :)
     
  34. braskys_scotch

    braskys_scotch Private E-2

    Sounds good. Should I wait for any further responses from you or anyone regarding the DeQuarantine.txt file, c:\qoobox folder (once I check and confirm if any files remain, or anything else prior to running the malware removal procedures you provided? Apologies if this is redundant but just want to be clear before proceeding. Thanks!
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like everything was restored. ;) You can still check the contents of the c:\qoobox\quarantine <-- quarantine folder if you like. But just continue on with the other procedures too.
     
  36. braskys_scotch

    braskys_scotch Private E-2

    The size of the c:\qoobox\quarantine folder is about 124 GB. Is this a problem? I'll review and possibly begin the malware removal tomorrow morning or evening depending on your response and how long it takes.

    Thanks for your help!
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just go through the malware removal procedures and attach all of the requested logs. Don't worry about anything else now at the moment. However we are going to reexamine the qoobox folder afterwards...
     
    Last edited: May 9, 2014
  38. braskys_scotch

    braskys_scotch Private E-2

    Logs attached here except for MGlogs.zip which hasn't yet uploaded successfully. Will attempt to upload in separate post. Thanks in advance.
     

    Attached Files:

  39. braskys_scotch

    braskys_scotch Private E-2

    Before I was only receiving a message that "Upload failed" for MSlogs.zip. Now I received this:
    "Your submission could not be processed because a security token was missing.

    If this occurred unexpectedly, please inform the administrator and describe the action you performed before you received this error."

    Please let me know if there's a simple fix to post the MG logs for you.

    Thanks again!
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try a different browser and let me know how you get on.
     
  41. braskys_scotch

    braskys_scotch Private E-2

    Same thing with Firefox browser (security token missing). Is something not set up correctly on my end when trying to upload this 8MB MGlogs.zip?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    YOu cannot upload an 8 MB log file. It is this large due to all the stuff that you had removed with ComboFix.. If you looked inside MGlogs.zip you will most likely see a very large newfiles.txt log. You can delete this from the ZIP and then upload the ZIP file.
     
  43. braskys_scotch

    braskys_scotch Private E-2

    Thanks. After removing the newfiles.txt log from MGlogs.zip that still leaves the zip file size at 2.67MB. Is there another .txt file that's not necessary for review and can be removed to trim the size, or is it best to just extract separate files from the MGlogs.zip and post in batches?
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    as a ONE time exception, upload the logs to mediafire.com
     
  45. braskys_scotch

    braskys_scotch Private E-2

  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not *quite* a complete set of logs. One text file is missing.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    Upload to mediafire the new MGlogs.zip
     
  47. braskys_scotch

    braskys_scotch Private E-2

    Did not see any error messages. Please see link for new MGlogs.zip file at mediafire.

    http://www.mediafire.com/?2y7by0j24udkykldm7dyyt0srr6wcdo
     
  48. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is quite a mess. It looks like lots WAS restored. And LOTS wasn't.
    All of what has been restored seems to still have the .vir extension on the end. Do you still see any files that have been restored with the .vir extension??
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Combofix does not remove the entries from the Qoobox folder when you run DeQuarantine. It just copies them back to the original location and strips the .vir extension.

    What you need to do is make sure everything has really been restored and then delete the C:\Qoobox folder to avoid having problems which such large log files. ;)
     
  50. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Chas. I understand that it is meant to strip the .vir extension.

    But look at this dequarantine.txt log in post #3 http://forums.majorgeeks.com/showthread.php?t=264372 compared to ours. Ours has the .vir extension before AND after it's supposedly dequarantined. Is that okay? :confused
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds