Can't Run ComboFix

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Burj, Jul 4, 2011.

  1. Burj

    Burj Private E-2

    I ran Superantispyware and MBAM. ComboFix said I had a free AVG running which I couldn't locate anywhere and then I kept getting error msgs for PEV.exe and pev.cfxxe saying they had encountered a problem and needs to close Runtime to terminate in an unusual way. I have run ComboFix before, now what? Also can't do a system restore.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks.

    Have you ran the official AVG Remover Tool (re-booting, re-running) before attempting to run ComboFix?

    http://www.avg.com/us-en/utilities

    *This reminder from the R&R ME FIRST:
     
    Last edited: Jul 4, 2011
  3. Burj

    Burj Private E-2

    I ran the AVG removal tool and it didn't work. So I reinstalled avg and then ran the removal and it worked. I still got the same errors with ComboFix. I continued with RootRepeal and MGTools. Attached are the logs. Thanks for your help!
     
  4. Burj

    Burj Private E-2

    Here are the attachments
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Did you "Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix" as instructed? Including Immunet3.0.2??

    Please put MGTools.exe directly onto your desktop as instructed in the R&R ME FIRST guide- not in this folder:
    Step 1:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * NOTE: You have two services from Sysinternals running but the filenames are unknown. Please tell me what they are.
    Step 3:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 4:
    Using Windows Explorer - navigate to and delete these left-overs:
    • C:\Documents and Settings\Shauna\Application Data\AVG10
    • C:\Program Files\AVG
    • C:\$AVG

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 5:
    Now run the below tool -
    TDSSkiller - How to run

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. Burj

    Burj Private E-2

    I did disable Immunet and all others. I think the systernals files are from RootKitReveal.
    I couldn't delete C:\WINDOWS\temp\Perflib_Perfdata_740.dat...says it's a NeroMediaPlayer file. It also says it was Created, Modified and Accessed all at Today, July 05, 2011, 12:24:18 AM
    Haven't tried a system restore yet.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Correct. :)
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    LOL Perhaps I didn't specifically indicate that the highlighted text should not be included in the script I gave. We'll remove it another way.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 3:
    Using Windows Explorer, navigate to and delete these:
    C:\WINDOWS\system32\avgfwdx.dll <-- file
    C:\Documents and Settings\All Users\Application Data\cK11467EpBcP11467 <-- folder

    Step 4:
    Please run this online scanner and attach the results.

    Using ESET's Online Scanner

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and the ESETscan.txt to your next reply.

    * Make sure you tell me if you had any problems running this procedure.

    *What malware problems are you still experiencing?

    dr.m
     
    Last edited: Jul 6, 2011
  9. Burj

    Burj Private E-2

    Thanks. I didn't notice your reply until now. Here are the 2 scan logs and the reg fix worked. Thanks again so much.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Using Windows Explorer - navigate to and delete:
    • C:\Documents and Settings\Shauna\Local Settings\Application Data\Conduit
    • C:\Documents and Settings\Shauna\Local Settings\Application Data\ConduitEngine

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now install the latest Sun Java Runtime Environment

    *What malware problems are you still experiencing?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds