Combofix with a twist

Discussion in 'Malware Help (A Specialist Will Reply)' started by decemberfall, Jan 24, 2010.

  1. decemberfall

    decemberfall Private E-2

    I know you guys are doing a great job hustling to get this combofix program everyone has been having corrected, but mine has a small twist. I did loose all my icons and everything (I am running a separate hard drive with all my important documents that was not affected), but also I had a particularly nasty virus and malware that it DID find a rootkit and remove it and it also found something else during scanning that made it restart to remove. I'm afraid to restore anything back that might have that malware in it (it's taken me a week to finally get it clean) and also I need to know how to safely remove those quarantined files that are infected as to prevent possible future infection, or does combofix do that itself?

    Also, i'm really mad at myself over this whole thing, it was the Internet security 2010 virus which i've gotten people to kill so many times, but it was cloaking itself as AVG and if I would have looked at it harder I would have noticed the yellow and red boxes were reversed and saved myself a LOT of headache! :)

    Thanks in advance you guys are awesome :)
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see this thread if running XP:

    Combo deleted everything..

    Do not attempt to restore anything on your own. Make no more changes to your PC. Just get us the De-Quarantine file so we can make a fix. Also get the ComboFix.exe file out of the Quarantine and back onto your Desktop.
     
  3. decemberfall

    decemberfall Private E-2

    small problem, it's not letting me find notepad...
     
  4. decemberfall

    decemberfall Private E-2

    nevermind, forgot they hid it in the windows nt folder...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's wordpad not notepad. You need to use notepad.

    Notepad is in your Windows folder.
     
  6. decemberfall

    decemberfall Private E-2

    okay, got it, but combofix did not restart at the end, so i just manually restarted, but when I logged back in it came up with 2 desktop.ini files that both say

    Code:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
    I also attached the log
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Okay a fix for ComboFix has come out also a tool has been made to automatically fix the problems caused by the previous version. Please follow along with the below.

    Download the new version of combofix.exe and save it to your Desktop overwriting the one you just copied there. DO NOT RUN IT YET!!! Just make sure you have the new version downloaded and saved.


    Now download this file > http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe


    You should be able to run it from any location but save it to your Desktop if possible. As long as Qoobox has not been tampered with, the tool shall be able to automatically do the below.

    • restore all the required files/folders
    • restore the perms
    • set the correct attributes for desktop.ini

    Now run the CFDQ-UsrPrf.exe program by double clicking on it.

    • Immediately after you run it, YOU MUST NOT reboot your PC. Don't do anything else but continue on with the below..
    • Now immediately run the new version of ComboFix that you saved to your Desktop earlier. This should cause a reboot of your PC after running if malware was detected and removed.
    • After reboot attach the C:\combofix.txt log.
    • Also please run the MGtools.exe program as specified here:Using MGtools Then attach the requesetd C:\MGlogs.zip file
    • (See: HOW TO: Attach Items To Your Post )

    Now tell us how things are working.

    • Do things seem to have been restored?
    • What malware problems are you having?
     
  8. decemberfall

    decemberfall Private E-2

    okay all ran, here are the logs!

    The icons all showed back up last night after running your quick fix, I did not get the desktop.ini files popping back up this time though.

    I had accidentally infected myself with the internet security 2010 that was cloaking itself as avg and didn't notice until too late that the yellow and red colors were reversed, and then as a result had the directdrd.com brower redirector causing me problems, which I think combofix caught on it's very first run yesterday(root kit) but things seem to be back to normal, other than avg really wants to run!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's have combo remove a few things.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\drivers\cjleesq.sys
    C:\WINDOWS\system32\drivers\hxcdjro.sys
    C:\WINDOWS\system32\drivers\tsbqwub.sys
    C:\WINDOWS\system32\drivers\wmxuv.sys
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now let AVG run and attach that log if it finds anything.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. decemberfall

    decemberfall Private E-2

    okay all have been ran, avg found nothing, but it took it about a week before it ever saw anything when I was infected... Logs attached! Things seem to be running faster already, thanks so much for all your help!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sadly, your system is never going to run fast with this little RAM ( you need twice as much ):
    Total Physical Memory 512.00 MB
    Available Physical Memory 85.82 MB

    Your logs are clean. I would suggest however that you uninstall your old Java versions as well as Ad-Aware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. decemberfall

    decemberfall Private E-2

    Funny you should say that, this computer is the Frankensteined version of its former self. When I built it in 2003 it was a 2.4 intel with 1 gig of ram, but since then I have had to replace the processor, lost a stick of memory, lost the modem(which doesn't really matter anyway), lost and replaced the secondary hard drive, replaced the power supply, video card fan, NIC, put a second card of usb ports in, and currently one of the ps2's isn't working and at least one of the on board usb's. I was using my laptop which recently the power adapter separated from the board, so I'm back to using this until I save up to replace both the desktop and get a net book.

    Thanks so much for all your help, I'll run the final clean up list and be more observant of pop ups. Thanks so much for all your help.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. It sounds like my old rig that is just parts hanging in a frame. LOL.
     
  14. decemberfall

    decemberfall Private E-2

    Got all but the newest java removed, but it doesn't give me the option of removing ad-aware. I tried in add/remove programs, it just does not give the option and I looked for an uninstall in the program folder.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you cant uninstall it through CCLeaner. :)
     
  16. decemberfall

    decemberfall Private E-2

    tried it said that the .msi file is missing to reinstall the program and then you can remove it. I went to lavasoft, downloaded it and tried to install it, it said it couldn't install because the .msi file is missing. Then it just updated itself and told me I need to restart to finish the update... but how the hell is it updating and running if the computer keeps telling me part of it's missing?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Another good reason to remove it. :)

    You need to use windows explorer to find and delete these: ( files first within folders..then the folders)

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
    C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
    C:\Program Files\Lavasoft\Ad-Aware
    C:\Program Files\Lavasoft
    C:\Documents and Settings\Brandy\Application Data\Lavasoft

    Now copy just the bold text below to notepad Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    That do it? :)
     
  18. decemberfall

    decemberfall Private E-2

    I get to here and get a message that says "ShellExt.dll Access Denied"
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Arrggghhh!! No wonder I hate it....LOL.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
     
  20. decemberfall

    decemberfall Private E-2

    It asked me to reboot, which I did, then the computer would not start. It tried once, and then the second time made me start it in "last known good configuration" and did not give me a log, I'm going to try it again...
     
  21. decemberfall

    decemberfall Private E-2

    tried it again, same result... i get a bsod stop screen for a second then it tries to restart right after the post screen, when I do "last known good configuration" it takes me back before where I deleted ad-aware...
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, crapola. If you can't install a working version, then I suggest that you post in the software forum for further assistance in removing this POS. :(

    Are you sure that the service is shut down first? Did you try doing the registry fix? Did you get a success message with that?



    Edit: We can try using ComboFix.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download ComboFix to your desktop but don't run it.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
    C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
    
    Folder::
    C:\Program Files\Lavasoft\Ad-Aware
    C:\Program Files\Lavasoft
    C:\Documents and Settings\Brandy\Application Data\Lavasoft
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Ad-Watch"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Did that work????
     
  24. decemberfall

    decemberfall Private E-2

    The registry fix did run successfully, i'm gonna work on the combofix now :)
     
  25. decemberfall

    decemberfall Private E-2

    here is the log
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do some more.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    yhlocemz
    bqzgmenp
    Lbd
    Lavasoft Ad-Aware Service
    
    File::
    c:\windows\system32\drivers\yhlocemz.sys
    c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
    c:\windows\system32\drivers\bqzgmenp.sys
    c:\program files\krvef.txt
    c:\windows\system32\drivers\Lbd.sys
    c:\program files\Lavasoft\Ad-Aware\AAWService.exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If you haven't yet removed MGTools, then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  27. decemberfall

    decemberfall Private E-2

    Here's the log, I have removed MG tools already but if you want me to redownload it, not a problem. Were all those part of Ad-Aware or had I picked something back up?
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You had picked up a few things. Be sure to keep SAS and MBAM and updated!

    You should be able to use windows explorer to find these last shreds of Lavasoft and delete them:
    c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
    c:\documents and settings\All Users\Application Data\Lavasoft

    And just to be safe, do re-download MGTool.exe and run it so I can double check your logs now.
     
  29. decemberfall

    decemberfall Private E-2

    here is the mgtool log
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\WINDOWS\adsojywq.txt
    C:\WINDOWS\winscv32.wwt
    C:\WINDOWS\temp\2355208c-1581-46fe-80ba-38ed716c94c0
    C:\WINDOWS\temp\3e7b6536-c6fe-424f-9e4e-9431bfd77944

    Tell me if you have problems with that. Also tell me what issues you are having.
     
  31. decemberfall

    decemberfall Private E-2

    Got all of them deleted. Haven't been having any issues, that's why i'm surprised we keep finding stuff hadn't had a problem since the internet security 2010 was killed for good. SUPERAnti-Spyware and Malwarebyte neither one have been finding anything on daily scans.
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is good to know. Just keep your AV and AS programs up to date and run them when you notice anything that may be a problem. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds