Combofix messed up my computer:(

Discussion in 'Malware Help (A Specialist Will Reply)' started by GearFour, Jul 17, 2012.

Thread Status:
Not open for further replies.
  1. GearFour

    GearFour Private E-2

    Hi,

    Recently my computer was infected with "Trojan.Dropper.BCMiner", it was linked to "C:\Windows\Installer\{48dd6613-37f1-e110-816b-cfb1749ac810}\U�000008.@".

    It has caused me alot of problems, and some expert told me to use combofix.

    I followed the steps given carefully, no mistake made. The Trojan was gone and everything was fine.

    Then i realised many of my computer's functionality went missing.

    So far i only can name a few problems and i have not discover the whole impact of what Combofix has done to my computer.

    These are what i have noticed:

    1) My computer has no sound, i check my sound drivers and they are up to date.

    2) All my photos and videos files are not accessible, it gives me some error box saying "Class not registered" while i click on photos and ''Windows Media Player cannot access the file. The file might be in use, you might not have access to the computer where the file is stored, or your proxy settings might not be correct'' when i try to open a video file. Are my files corrupted and unrecoverable?

    3) From Firefox download window, i can no longer use the option of "Open Containing Folder", nothing happened when i click that.

    4) Some control panel settings are not accessible: 1) under User Accounts, nothing happened when i click on ''Change User Account Control settings"
    2) same thing for ''Device Manager" in Control Panel\All Control Panel Items\System
    I am using administrator account by the way.

    Hope someone out here can help me restore my computer to how it originally was, excluding the trojan. Thanks!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My best thoughts are either you can attach the combofix log if it created one, usually right on C:\

    Or... have you considered a system restore if you have any old points to return to before you used Combofix?
     
  3. GearFour

    GearFour Private E-2

    Hi, i have noticed that combofix also messed up my network connection. But the strange thing is me able to access the internet despite this issue. Combofix also messed up my system restore option, i have attached a screenshot of it.
    Combofix log has also been attached. Thanks!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer


    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    c:\windows\SysWow64\drivers\utmzndg2.sys
    c:\windows\SysWow64\shoCA8B.tmp
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. GearFour

    GearFour Private E-2

    Hi,
    i tried the OTM and this is the log.

    All processes killed
    ========== FILES ==========
    c:\windows\SysWow64\drivers\utmzndg2.sys moved successfully.
    c:\windows\SysWow64\shoCA8B.tmp moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 56475 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: See Toh
    ->Temp folder emptied: 345698721 bytes
    ->Temporary Internet Files folder emptied: 17948560 bytes
    ->Java cache emptied: 1 bytes
    ->FireFox cache emptied: 275171566 bytes
    ->Flash cache emptied: 4945 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 401408 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 110170 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 253684565 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 49648108 bytes

    Total Files Cleaned = 899.00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 07182012_095906

    Files moved on Reboot...
    C:\Users\See Toh\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File C:\Windows\temp\kls950E.tmp not found!

    Registry entries deleted on Reboot...


    By the way, do i use the system restore only as a last resort?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I thought you said system restore was knackered? You even attached a screenshot of it showing me.

    Let's continue on now, did you not run FRST yet? :confused
     
  7. GearFour

    GearFour Private E-2

    Ops, i made a mistake. I was thinking the message below are steps to restore my computer. I just done the scan, here is the log:)
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    • Now attempt to boot normally.
    • Run FRST like you did before and attach that log too for me to see.
     

    Attached Files:

  9. GearFour

    GearFour Private E-2

    Done both fix and scan. Here are the logs:)
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Has any of the above made any difference? Reboot the computer if not done so already and let me know whether anything has changed regarding the problems you outlined.
     
  11. GearFour

    GearFour Private E-2

    1) My computer has no sound, i check my sound drivers and they are up to date.

    2) All my photos and videos files are not accessible, it gives me some error box saying "Class not registered" while i click on photos and ''Windows Media Player cannot access the file. The file might be in use, you might not have access to the computer where the file is stored, or your proxy settings might not be correct'' when i try to open a video file. Are my files corrupted and unrecoverable?

    3) From Firefox download window, i can no longer use the option of "Open Containing Folder", nothing happened when i click that.


    4) Some control panel settings are not accessible: 1) under User Accounts, nothing happened when i click on ''Change User Account Control settings"
    2) same thing for ''Device Manager" in Control Panel\All Control Panel Items\System
    I am using administrator account by the way.

    Only Point 3 was fixed.
    Even the system restore and the network were not fixed.

    Saddening:(
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I am seeking advice from one of the elders. ;) Hang in there, yes?
     
  13. GearFour

    GearFour Private E-2

  14. GearFour

    GearFour Private E-2

    any findings?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please give it chance. As it is in the UK it's half past five in the morning and I have only had 4 hours sleep since monday night. I'm seeking advice I already told you that. I'm still online just to "wind down" before I sleep. ;)
     
  16. GearFour

    GearFour Private E-2

    Sorry, i didn't know it is that late at your area. I will wait then.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  19. GearFour

    GearFour Private E-2

    There is this part in the link that states "You must uninstall all but one antivirus program."

    I'm planning to keep my KasperSky Internet Security. Are Malwarebytes Anti-Malware, Spy-Bot Search & Destroy, SuperAntiSpyware even considered anti-virus software? Sometimes these programs managed to find more malicious softwares that KasperSky can't. Is it really wise?

    I'm not trying to question your knowledge, but is the Malware Removal Guide really related to the problems combofix caused as i have mentioned earlier?
     
  20. GearFour

    GearFour Private E-2

    i forget to state that only Malwarebytes managed to find out about the trojan earlier before i did the combofix.

    Hope to clarify everything before i proceed:)
     
  21. GearFour

    GearFour Private E-2

    This was the Qoobox quarantee file from Combofix, i forgot to post it earlier, hope it helps.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Huh??? :confused:confused I have not a CLUE what you are referring to here. I think the problem is actually more like this. You download porn and wares which has caused damage. NOT combofix.

    Are you ever going to attach the rest of the logs I requested or are you going to keep attaching items that we did not request?
     
  23. GearFour

    GearFour Private E-2

    I thought at first i said my computer got infected, after i did combofix the infection was cure.

    But combofix did damages like these mentioned:

    1) My computer has no sound, i check my sound drivers and they are up to date.

    2) All my photos and videos files are not accessible, it gives me some error box saying "Class not registered" while i click on photos and ''Windows Media Player cannot access the file. The file might be in use, you might not have access to the computer where the file is stored, or your proxy settings might not be correct'' when i try to open a video file. Are my files corrupted and unrecoverable?

    3) Some control panel settings are not accessible:
    -under User Accounts, nothing happened when i click on ''Change User Account Control settings"
    -same thing for ''Device Manager" in Control Panel\All Control Panel Items\System
    -i can't use system restore

    4) It shows my network connection is not connected, but strangely i can access the internet

    These problems weren't there before combofix was executed.
     
  24. GearFour

    GearFour Private E-2

    So what i'm hoping to achieve is to revert to how my computer originally was with my files working, computer sound working etc.
    I'm thinking that Combofix quarantine some of the important system files, causing all those problems which i have listed.
     
  25. GearFour

    GearFour Private E-2

    Anyway, if i were to continue with the Malware Removal Guide. I'm still stuck at this part.

    "You must uninstall all but one antivirus program."

    I'm planning to keep my KasperSky Internet Security. Are Malwarebytes Anti-Malware, Spy-Bot Search & Destroy, SuperAntiSpyware even considered anti-virus software? Sometimes these programs managed to find more malicious softwares that KasperSky can't. Is it really wise to remove all and keep one?
     
  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, GearFour
    No, they are not... but please make certain that Spybot's TeaTimer is disabled.

    How to disable Spybot's TeaTimer

    *To get to the root of your problems, you must provide Kestrel with any requested logs.
     
  27. GearFour

    GearFour Private E-2

    Now i'm stucked at the part where i have to disable UAC.

    because of the problems i have mentioned earlier:

    3) Some control panel settings are not accessible:
    -under User Accounts, nothing happened when i click on ''Change User Account Control settings"
    -same thing for ''Device Manager" in Control Panel\All Control Panel Items\System
    -i can't use system restore

    But maybe i have already disabled UAC in the past, how do i double confirm?
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Go to start > type in "cmd"
    • Click on cmd.exe > and paste in the following:

    After you enable or disable UAC, you will have to reboot your computer for the changes to take effect.

    The to re-enable (once we have totally finished) Same procedure except paste this in:

    You should receive a success message saying: "The operation completed successfully"
     
  29. GearFour

    GearFour Private E-2

    I encountered a problem while running MGTools, do i click ok or cancel?
    I have attached a screenshot.
     

    Attached Files:

  30. GearFour

    GearFour Private E-2

    I click cancel and nothing has happened.:confused
     
  31. GearFour

    GearFour Private E-2

    Screenshot
     

    Attached Files:

  32. GearFour

    GearFour Private E-2

    I tried using the MGtools again, and this time i click "OK" when the Process.dll error appeared. I managed to get the log, but i'm not sure if it's the complete log since there is this error while running it. I have attached the 4 log as requested.

    Anyway, i tried to Re-register system DLLs just now. And the "no sound'' problem in my computer is resolved. So now it's just left with these 3 problems.

    1) All my photos and videos files are not accessible, it gives me some error box saying "Class not registered" while i click on photos and ''Windows Media Player cannot access the file. The file might be in use, you might not have access to the computer where the file is stored, or your proxy settings might not be correct'', "Server execution failed"when i try to open a video file. Are my files corrupted and unrecoverable?

    2) Some control panel settings are not accessible:
    -under User Accounts, nothing happened when i click on ''Change User Account Control settings"
    -same thing for ''Device Manager" in Control Panel\All Control Panel Items\System
    -i can't use system restore

    3) It shows my network connection is not connected, but strangely i can access the internet
     

    Attached Files:

  33. GearFour

    GearFour Private E-2

    what do i do next? o.o
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    WAIT. Just WAIT! Thanks. You need to be patient here. Don't BUMP!
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. You will have to post in the software forum regarding the outstanding problems. I have finished removing malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  36. GearFour

    GearFour Private E-2

    This Part

    If you are running Win 7, Vista, Windows XP or Windows ME, do the below:

    Refer to the cleaning procedures pointed to by step 7 of the READ ME
    for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.

    For Windows 7

    1. Click Start
    2. Right click Computer > Properties > Choose Advanced System Settings option in left menu listing.
    3. Click System Protection tab
    4. Then highlight the drive you wish to turn off System Restore and click Configure (Image 1)
    5. Then choose Turn off system protection (Image 2)
    6. Click Apply > OK

    I right-click computer and then properties, nothing happened. Exactly like those system problems i told you earlier.
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just do what you can of those final steps and tell the guys and gals in software all about the issues you have.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds