Combofix will not run / locks up

Discussion in 'Malware Help (A Specialist Will Reply)' started by amos1001, Dec 4, 2010.

  1. amos1001

    amos1001 Private E-2

    Kestrel13! suggested i post a new thread here, and link to a previous thread.


    http://forums.majorgeeks.com/showthread.php?t=227754

    The problem is this. I thought i had an infected machine because of a link i clicked on. I have used Combofix in the past with excellent results, so I decided to try it this time.

    It locks up. Combofix will start, and when it gets to the screen that says "times may easily double on a badly infected machine," it never goes past that.

    Kestrel walked me thought malware removal, and we never found any infections on my system.

    when I run the repair console and FIXMBR it says i have an un-standard version of the MBR. however when i run rootkit it says my MBR is fine.

    Kestrel suggested that maybe another one of you might have an idea as to why Combofix locks up, and what I can do. If you read the other thread you will see where we have been and what we've done.

    thanks
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, amos1001

    Knowing that Kestrel13! is very thorough in her log reviews, I can only suggest that you run a few of the Free Online Scanning Tools from the Alternative Scans guide to help remove your suspicions of an infection.

    dr.m
     
  3. amos1001

    amos1001 Private E-2

    Yes, I agree. My thoughts are than if I had an infection she would have found it. But since she didn't find one what could be causing combofix not to run?

    Can you think of anything? Some program that, while not malware or an infection, is causing combofix to lock up?

    thanks for any suggestions!
    -amos
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  5. amos1001

    amos1001 Private E-2

    I disabled it, but i didn't uninstall it. I"ll try that now.

    Also, I was unaware of those issues. I've been using AVG but it seems to slow down my booting so much (older computer, celeron 1.5G, 2GB ram)

    I'll post back in a bit.
     
  6. amos1001

    amos1001 Private E-2

    no luck, it still locked up. this time i left it for 30 min to see if it might do something, but no.

    i'm downloading AVG now, based on your info about clamwin. thanks.

    any other ideas about combofix locking up? i thought about trying an older version if i could find one, just to see if it ran. i thnk the last time i used it on this box (with success) was about 6 months ago, maybe a bit more.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Very bad idea if you ever need ComboFix to run again. ComboFix will not run at all if AVG is installed.

    Based on what I read in your other thread, it is highly possible that you have some Windows corruption which may be why you cannot run ComboFix and also MGtools did not run properly either. You could have registry or file system corruption or driver issues.

    You should never have been running ComboFix like you were running it anyway. It is a highly specialized tool with special purposes and should not be run just for any time something goes wrong on your PC. The fact that ComboFix hung on you many times and necessitated hard reboots could have even cause you more problems with Windows. The only real fix may be to reinstall however if the only problems you have are inability to run ComboFix then you should just ignore it. I will give you a couple things to try down below but I'm not sure they will help.


    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Now try running this: Resetting Registry and File Permissions

    Then reboot and you can retry running ComboFix, but if it does not run, I suggest that you either forget about it or bite the bullet an do a reinstall or a repair install.
     
  8. amos1001

    amos1001 Private E-2

    well, i tried both of those. they seemed to be doing a lot, but i don't guess there was a report.

    still no go on combofix or mgtools. i guess you're right, i should just forget about it.

    question... if i decide to do a clean windows install the disk i have is the one that came with the computer. toshiba recovery disk. will that wipe the MBR or should i do something else (like fdisk) before i run the recovery?

    thanks for all your help.
     
  9. amos1001

    amos1001 Private E-2

    by the way, i installed AVG and ran its scans.
    it found 3 items in the rootkit section.

    "Warning";"IRP hook, \FileSystem\Cdfs IRP_MJ_FILE_SYSTEM_CONTROL -> tfsnifs.sys GetSystemType+0xCA0A";"C:\WINDOWS\system32\dla\tfsnifs.sys.rmv";"N/A";"12/5/2010, 8:13:48 AM"
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. amos1001

    amos1001 Private E-2

    wow emma i thought you'd given up on me. welcome back.

    ok i have a strange situation.

    i tried the GMER as per the linked instructions. the scan ran for EVER and finally locked up. the window said "not responding."

    so i had to do a cold boot. when i did, windows took another forever to boot. i gave up and booted to safe mode, which worked a bit slow but ok.

    my guess was that the temporary file that GMER was in the process of creating somehow is attempting to be loaded into memory, and overwhelming my system. from safe mode i ran disk cleanup, and cc cleaner. then i booted to windows. it FINALLY will get to windows, but it takes 10 minutes or so.

    currently i'm executing sfc /scannow,

    do you have any ideas? looks like i broke it this time.
     
  12. amos1001

    amos1001 Private E-2

    hi again,

    ok i've got it booting again. it's still slow, but not as bad as it was.
    i ran cc-cleaner, reset my page file and hibernate file. (actually i disabled hibernation for now). page file is system controlled now. and i uninstalled AVG.

    it runs slow, and applications sometimes lock up. if i didn't know i had 2gb of ram, i'd think it needs more. but it has 2gb, 2 1g sticks, and it's topped out.

    it says i have 1.87gb, but the ram is shared with the video.

    the boot is better, but it still drags as the little animation moves across the screen (winxp home). sometimes the animation stops. it didnt do that before.

    i was trying to run the GMER scan when it locked up. is there some file GMER would use that was terminated incorrectly? something i can delete?

    thanks
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As a suggestion, I would like you to run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    If you already uninstalled it, you can get a fresh copy here:
    MGtools
     
  14. amos1001

    amos1001 Private E-2

    hi tim,

    i've never gotten MGtools to run without locking up.

    Here's what I was able to get, though. The first file MGLogs1.zip is the result of the executable (which runs getrunkey.bat after extracting files).

    getrunkey never finishes, it just sits there forever (ironically after it instructs me to wait for the file to finish).

    based on Kestrel's instructions from the other day, i also ran shownew.bat. the resulting output is attached as MGlogs2.zip

    thanks for any help.

    by the way, based on advice from the others here and results from the scans i've done, it must not be malware. but this slowness is pretty bad. in case you didn't get this part, it occurred when i had to do a cold boot when GMER locked up. it appears to have something to do with my hard drive. when it's doing that, taskmanager shows my cpu usage between 98 and 100%. the processes tab doesn't show anything using excessive cpu. system idle processes is between 92-99%. but until the hard drive stops churning the system is PAINFULLY slow. just moving the mouse across the screen is slow.

    i've cleaned out all the temp files, including java's temp. and currently i've uninstalled my antivirus (just a temporary measure). it's a bit better, but still slow as i've described. the first time rebooting after the GMER lockup the windows "moving boxes" or whatever you'd call them moved really slowly, and even stopped. it took 10 min or more to even boot. safe mode was a little better.

    i turned off virtual memory, deleted the pagefile and then restarted it (in case it was corrupted). windows tells me my recommended size is 2877mb, so i have it as a static 2877mb size (custom size, min 2877, max 2877).

    although the drive is small (55gb) there's over 19gb free.

    thanks
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All of this sounds like issues with your system, as opposed to being a malware issue. It is possible you are having hard drive problems. I would suggest that you post in the software forum as the inability to run both MGTools and ComboFix may just be symptoms of either a hardware or software problem. You may need to try what Chaslang indicated> a repair install or a complete reformat and install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds