ComboFix Deletion (Quarantine?) of User Files

Discussion in 'Malware Help (A Specialist Will Reply)' started by braskys_scotch, Apr 25, 2014.

  1. braskys_scotch

    braskys_scotch Private E-2

    The files I have randomly viewed in my libraries appear just as they did before this whole computer repair tech combofix mess began. Are we seeing anything in the logs et al that's wrong or would have necessitated / justified the combofix program in the first place? I'm thankful to have the files restored, but I still don't know what it is that needs to be addressed with respect to the performance of my computer going forward. Are you seeing things you would expect to see, irregularities, red flags, etc?

    Thank you
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DeQuarantine::
    C:\QooBox\Quarantine\C\Program Files (x86)
    QUIT::
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Is there a C:\Dequarantine.txt?

    Can you check again and see if anything is missing at all please and let me know?
     
  3. braskys_scotch

    braskys_scotch Private E-2

    Hi there,

    No c:\combofix.txt was produced from running the combofix program with the KILLALL lines you wrote. I searched for any files by that name and none associated with tonight's running of combofix turned up. I did attach the DeQuarantine.txt that was produced in zip format.

    My documents appear to be fine. My photo and video files are all tagged with the .vir extension. Presumably we're not out of the woods quite yet. Thank you for your guidance.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me exactly which files and folders you have issues with. For the files it's just videos and pictures that still have .vir extensions, correct? Does anything else have that extension?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's scan in a few key folders.


    Using Internet Explorer download ( by using right click and select Save Target As ) and save the below to your PC (save it into the C:\Mgtools folder). If the file does not download as FindVir.bat then right click on it and select rename and change the name to FindVir.bat because the sometimes downloads save it as FindVir.txt. After renaming, right click and select Run As Administrator. Wait for it to finish ( the black command prompt box will disappear ). It could take quite awhile if there are lots of .vir files.

    FindVir.bat


    When it finishes, there will be a VirFix.zip file in the C:\MGtools folder. Attach this file here. If it is too large to attach, use mediafire like you did previously.
     
  6. braskys_scotch

    braskys_scotch Private E-2

    Thanks. Here's the VirFix.zip file.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now let's try a fix that will attempt to remove the .vir file extension from over 27000 files Download the below Fix1.zip file to your Desktop and then extract the Fix1.bat file from inside the ZIP file. Then right click on the Fix1.bat file and select run as Administrator to run it.

    Fix1.zip


    After the fix completes, the command prompt window should close. When it finishes, rerun the same FindVir.bat file that you previously ran and attach the new VirFix.zip file in the C:\MGtools folder.

    I'm not sure the Fix1.bat file will be able to fix all files in one run because there are multiple user accounts that have files with the .vir extension.
     
    Last edited: May 27, 2014
  8. braskys_scotch

    braskys_scotch Private E-2


    Hello.
    Is there a different file that the link is supposed to trace to? When I download this (rt click, save as, etc), it saves as VirFix.bat, and there is no additional file named Fix1.bat.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it again now. The link was broken.
     
  10. braskys_scotch

    braskys_scotch Private E-2

    VirFix.zip attached. Thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Well that still shows there all the same files with the .vir extension. So two conclusions can be made:
    1. Something stopped the file renaming from occurring properly.
    2. The actual file without the .vir file extension already exists and thus the rename would fail. This would mean you could delete the .vir files as dups.
    Did you ever check to see if number 2 is the case? Are the .vir file actually duplicates?
     
  12. braskys_scotch

    braskys_scotch Private E-2


    Unfortunately, the picture and video files tagged as .vir files are not duplicates, and I have not found them under any other user tree of files. In each of the picture and video folders there are two desktop.ini files. Is this causing any issues?

    Also, I'm assuming the methods we've employed are only addressing a single set of user files. I skimmed the other user folders/files, and the .vir extension is prevalent in most, if not all, folders/files.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on one of the .vir files and select Rename. Then just remove the .vir extension. Does this work or do you get an error message?

    Not a problem.

    No. See my last sentence at the end of message # 57.
     
  14. braskys_scotch

    braskys_scotch Private E-2

    The renaming strategy has seemed to work on the few files I've renamed. There's only the standard message that renaming could affect the functionality of the file.

    Should I proceed to rename all in each user profile?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds