ComboFix

Discussion in 'Malware Help (A Specialist Will Reply)' started by grizzly8u, Mar 22, 2010.

  1. grizzly8u

    grizzly8u Private E-2

    My computer got infected and although I successfully removed(I think) the virus My Documents are now gone. I happened across this thread: http://forums.majorgeeks.com/showthread.php?p=1445130 and it appears I have a similar problem. I ran malwarebytes and combofix. I also used erd restore. Any way to get my stuff back?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the C:\Qoobox\Quarantine folder so we can see what needs replacing.
     
  3. grizzly8u

    grizzly8u Private E-2

    Here you go. Thanks for the quick reply! Roger
     

    Attached Files:

  4. grizzly8u

    grizzly8u Private E-2

    Just found this in the root. Don't know if it's helpful or not...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the new fixed version of combofix.exe and save it to your Desktop. DO NOT RUN IT YET!!! Just make sure you have the new version downloaded and saved.

    Now download this file > http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe

    You should be able to run it from any location but save it to your Desktop if possible. As long as Qoobox has not been tampered with, the tool shall be able to automatically do the below.
    • restore all the required files/folders
    • restore the perms
    • set the correct attributes for desktop.ini
    Now run the CFDQ-UsrPrf.exe program by double clicking on it.
    • Immediately after you run it, YOU MUST NOT reboot your PC. Don't do anything else but continue on with the below..
    • Now immediately run the new version of ComboFix that you saved to your Desktop earlier. This should cause a reboot of your PC after running if malware was detected and removed.
    • After reboot attach the C:\combofix.txt log.
    • Also please run the MGtools.exe program as specified here:Using MGtools Then attach the requesetd C:\MGlogs.zip file
    • (See: HOW TO: Attach Items To Your Post )
    Now tell us how things are working.
    • Do things seem to have been restored?
    • What malware problems are you having?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @TimW,

    I don't believe this user has the problem of the old ComboFix bug which deleted user files. The Dequarantine and Combofix.txt log show a current CF version and no deletion of and user files. ComboFix was just run from an incorrect location. There was however an infection in atapi.sys
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    @ Chaslang: Yes, I saw the replacement of the atapi.sys file. And no listing of previous run removals.

    @grizzly8u: Please follow all the instructions here;

    READ & RUN ME FIRST. Malware Removal Guide

    So we can see what your issues are.

    PS: Make sure you put ComboFix directly on your desktop.
     
  8. grizzly8u

    grizzly8u Private E-2

    I am missing My Documents and several sub-folders under My Documents. Before I go through all the malware removal steps I just wanted to make that part clear. Let me know so I don't further mess something up and make it totally unrecoverable before I run all these things. Again, thanks!

    P.S.The ComboFix was included in Hirens BootCD if that makes a difference.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why were you using Hiram's boot disc? Was it during that usage that you lost documents?

    We can't see what is happening in your system without you doing the Read and Run First instructions ( you can leave out running ComboFix ).
     
  10. grizzly8u

    grizzly8u Private E-2

    Was using it to get rid of the initial infection. I couldn't boot to safe mode or anything thus Hirens disk. Ran the ComboFix from that disk. It was his latest version 10.2 I think. And yes I thought I had it all working right up until the point I went to look for My Documents. Will run the tasks as directed. Thanks,
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do run the scans so we can see what you attach. Thing is, the documents may have gone south when you had to use Hiram's and may not be retrievable.
     
  12. grizzly8u

    grizzly8u Private E-2

    I hope not that far south. . . I ran Recuva just to see if any were visible. Didn't recover any of them or anything else cause I know what happens if you write over something. There are several present that appear recoverable but of course I'd like it all . . .That was before I discovered your site. Have not done a thing since seeing your site other than at your direction.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans ( RootRepeal, SAS, MBAM, MGtools.exe ) will not remove or hurt any chance of recovery. It is just to see if there is malware present. I am afraid you may need to post in the software forum as well to get assistance in file recovery software.
     
  14. grizzly8u

    grizzly8u Private E-2

    Well let's hope it's all there when you do your magic!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'll be here when you are ready.
     
  16. grizzly8u

    grizzly8u Private E-2

    Ok here's the results of all the various tests requested. As we discussed I did NOT run ComboFix. It appears that things are back to normal with one anomaly. Whatever took over hid Internet Explorer and when I did a search for Iexplore it continually found the C:\i386 files and then opened my Gmail drive logon screen over and over until I cancelled it. I ran all the tools and followed the directions to the letter and stopped short of disabling the system restore part. Please let me know how to proceed. Thanks, Roger
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still missing the requested log from MGtools.
     
  18. grizzly8u

    grizzly8u Private E-2

    Sorry 'bout that. I had it. Missed in the upload. Thanks, Roger
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. You have numerous user account under C:\Documents and Settings. Some appear to have been corrupt as some point.

    However, this is not a malware issue. You do need to post in the software forum for further assistance.

    Sinne you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  20. grizzly8u

    grizzly8u Private E-2

    The size mismatch stuff in the root repeal logs are not of concern?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it is not a concern. It is Microsoft SMS client.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds