Combofix is not available at this time...

Discussion in 'Malware Help (A Specialist Will Reply)' started by opal219, Dec 13, 2009.

  1. opal219

    opal219 Private First Class

    Hello,
    I'm following through the removal of spyware in order of operation and when I attempt to download combofix, I'm getting this message

    "ComboFix is currently not available for download until an issue with the program is resolved. Please be patient while the developer fixes the program and makes it available once again. As more information becomes available, we will update this page."

    Should I just stop now until it becomes available again or start installing and running the other programs?
     
  2. opal219

    opal219 Private First Class

    Alrighty - I went back and saw that someone in here updated the instructions page to say - skip and continue - so I have.
    Attached will be my SAS log, my mbam log and my MGtools log.

    I was unable to download combofix.
    I was able to download Rootrepeal but unable to run it. When I clicked on the files menu to select my drive, it was blank - no drives appeared to select. I tried several times and got the same result. I took a screen shot of that if anyone would like that attached also.

    The issue that I'm concerned with now is that after all the scans that I still have two instances of
    ati2evxx.exe
    present in my task manager processes list. When searching for what this is, results said to get rid of them. I'd like to do that safely and am not sure how.

    As per instructions, I have not yet uninstalled anything.
    I left the new programs that can run resident and have a couple others also so I am sporting a lot of protective gear - hopefully preventing anything new from happening.

    Also, the instructions said not to download anything else while in process of scans and I had an auto update of windows happen before I could stop it.

    and now for the attachments:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. It is for your ATI Graphics Card. See this:
    http://www.liutilities.com/products/wintaskspro/processlibrary/ati2evxx/

    Your logs are clean but I suggest that you rethink the installation of Ixquick Toolbar which you have. It is consider malware by some, and questionable at best by others. Examples below:

    http://spywaredlls.prevx.com/RRDIFB44914620/IX_QUICK.DLL.html
    http://www.systemlookup.com/CLSID/5190-ixquick_dll_ix_quick_dll.html

    It is your choice if you knowingly installed it and have no problems with it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  4. opal219

    opal219 Private First Class

    yeah! clean logs.. I do love the sound of that.

    Re: Ixquick toolbar - I've used ixquick as my default search engine for years. When they came out with their toolbar a couple of years ago, I was probably one of the first to try it - and in general I dislike toolbars taking up my desktop real estate (and now I have two I use all the time)
    I use a couple of the functions on this tool bar on almost every page I navigate to on line. With my lousy eyesight, it's got an easy to access and use magnification tool that I would be lost without.

    Anyway, now should I also be changing msconfig back to other than normal start up?
    Cleaning old restore points out?
    Taking SAS and MAM off the start up list and leaving them as stand alone scanning tools?

    I also noticed that there's no mention in the cleaning or protection instructions of LavaSoft's Adaware - has this program run it's course and been reduced to not worth mentioning anymore? It comes up with my start up process and runs full time on my system. Should it be replaced with another program?

    Thank you so much for your time.. off to uninstall MGTools
     
  5. opal219

    opal219 Private First Class

    I know this is going to set me back in the pulling my hair out help wanted line but I have
    post cleaning errors happening.

    Problem 1
    Part of the proceedure had me uninstall things I don't use anymore.

    One of these was an older model HP scanner.
    The uninstall seemed to go just fine, however, it left the program listed on my control panel add/remove programs list without a button to do anything with it.

    Now, when I start the computer, fire up a browser, open random programs a little window pops up with 1606 error referencing the scanner. "could not access network loaction \digital imaging - with retry and cancel in the box. This happens when I'm doing nothing related to printing or scanning.

    I have a whole bunch of .dll files still on the computer that are HP related and I no longer have any HP devices.

    Problem 2
    I click a link anywhere.. email, here, other sites and get this message.

    windows cannot access the specified device, path or file. You may not have the appropriate permissions

    to access the item.

    across the top of the little box that the above text is in, I see this file path. The forward slashes and dots are all that appear and I cannot expand the box to see the full path.

    c:\program files\jave\jre6\lib\deploy\jqs\ff\..\..\..\bin\jqsnoti...

    I click OK on that box and SOME of the links do what they would have without the message . I sent myself a video from a second email account (scanned and clean) as a test. The vid downloaded but when I tried to play it, I got that message and then clicking OK just closed the error box and nothing happened.

    I redownloaded and reinstalled java hoping that would help but am getting the same results when clicking links.

    Problem 3

    Using either the mouse keys or ctrl C / Ctrl V attempts to highlight text and copy/paste from web pages are unsuccessful.

    I've used start..run.. clipbrd to view what's happening there. When I highlight and copy from notepad, the

    text shows up - trying to copy from the address bar on firefox, or the little window for properties on an image shows or just web page text, I get no copy results - just a blank clipboard.

    If this is no longer a malware issue, I apologise and will take it to the proper category. (software?)

    edited for run on sentence.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may or may not be related to malware. Since ComboFix is back online, please run it and attach the log per the instructions in the READ & RUN ME. Also do the below.

    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r
     
  7. opal219

    opal219 Private First Class

    thank you for your time on this. I got it straightened out by uninstalling and reinstalling my browser (firefox) I'm no longer getting the error pop ups and the copy paste functions returned.. all systems go now
    thanks again!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds