Combofixdeleted all my files

Discussion in 'Malware Help (A Specialist Will Reply)' started by kevinabrownlee, Jan 24, 2010.

  1. kevinabrownlee

    kevinabrownlee Private E-2

    I need help. i ran combofix and it deleted all my documents and settings. Restored some with fixes I've read, but I can't get them all back - help - please
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should not be running fixes given to some one else! Only follow instructions directly given to you.

    A recent bug that just appeared with ComboFix is causing it to delete important files.

    Get the C:\QooBox\ComboFix-quarantined-files.txt and attach it here so we can attempt to work up a fix to restore everything. We will need to use ComboFix to restore everything so we will have to restore it to since this bug has deleted ComboFix.exe from the Desktop too (or from whereever it was run).

    We have already fixed several PCs where this problem has occurred.

    Do not attempt to restore anything on your own. Make no more changes to your PC. Just get us the De-Quarantine file so we can make a fix. Also get the ComboFix.exe file out of the Quarantine and back onto your Desktop. If you don't know how to get this file back on to your Desktop, just tell us.
     
  3. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combofix deleted all my files

    i know i should not have tried and run anything myself, but I felt helpless and rushed into it without thinking - i attached file - i hope you can help - i'm dying here
     

    Attached Files:

  4. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combofix deleted all my files

    also attached these files - files created after i ran fixes I sHOULD NOT have
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you already ran a CFScript.txt with only the below in it? Was it exactly this fix?
     
  6. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combo fixdeleted all my files

    yes, i believe i ran a CFscript with that information in it - really bad? right? - again - any help - is so apprecaited.
     
  7. kevinabrownlee

    kevinabrownlee Private E-2

    and... some files returned to my documents - but all the folders with documents in them(that were in my documents ) are still missing and every folder i had in my desktop is missing the files and other content they once held
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not run exactly that fix since it would have returned them. Hang on while I look at your logs and give you a fix to run. Is ComboFix.exe on your Desktop now?
     
  9. kevinabrownlee

    kevinabrownlee Private E-2

    combofix is on my desktop

    yes - combofix.exe is on my desktop
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then run the below and wait for it to finish running. Do not do anything else on your PC while running and make sure to close your browsers before running.


    NOTE: This fix only applies to this user! It will definitely not work for anyone running Vista or Win 7 so do not attempt
    to use this fix if you are not the user who created this thread.



    Now we need to use ComboFix to restore files. This will only restore, it will not delete anything.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing
      ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad ( Click Start > Run, type notepad then press Enter ) and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall. Be patient. It can take awhile for all files
    to restore. You will slowly notice things appearing on the Desktop. Wait for ComboFix to finish. It will show you a De-Quarantine log when it is
    finished.


    After reboot, tell us how things are looking. You should check each user account.
     
  11. kevinabrownlee

    kevinabrownlee Private E-2

    i ran the program, but many files still do not show up - although under q00box / quarantine / it seems as most files still reside in that directory
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach the De-Quarantine log.
     
  13. kevinabrownlee

    kevinabrownlee Private E-2

    de-quart txt

    is this it
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember to attach logs! Yes this is a log from a De-Quarantine but it is the same as the last one

    Give me a couple examples of files that are not being restored.
     
  15. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combofix deleted all my files

    files not being restored are -

    file folders that had documents in them - located in my documents are missing - along with the files they contained

    another example is i have 7 or 8 folders on my desktop - some of these folders have folders in them - the folder structures remain - but they are empty
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Combofix deleted all my files

    I need exact details. Give an example of a full filename and path. Your De-Quarantine logs shows the files from My Documents were restored.

    Again, you must be specific.

    You have hundreds of infected files in your quarantine and you don't want to restore these by mistake
     
  17. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combofix deleted all my files

    on the desktop the folders CHDE, project crossroad, daddy does, etc are empty - they each contained file types such as - word, jpeg, and pdf

    in my documenst, there were folders that were named as follows: my_documents_from_dimension..... - while was full of files - it is missing, another example is a folder named my_documents_from_insprion... and was full of files - it is missing -

    tell me where to look to give you an example from a log, etc... i apologize for my ignorance in these matters
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Combofix deleted all my files

    According to the ComboFix-Quarantine log you posted back in message # 3, none of these were deleted by ComboFix as they do not appear in the log. Check it yourself and see if you see any of the folders or files you are mentioning.
     
  19. kevinabrownlee

    kevinabrownlee Private E-2

    Re: Combofix deleted all my files

    i have checked for them as far as where they were located before and they are missing. could there be multiple problems because i started and stopped the process a few times before i sought help
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Combofix deleted all my files

    Anything removed by ComboFix would be in its QooBox folders. Examples can be seen by looking at your log. You can see things from 2008 which you never cleaned up. Like the below
    Code:
    2008-02-07 15:26:05 . 2008-02-07 15:26:05           13,426 ----a-w-  C:\Qoobox\Quarantine\C\WINDOWS\system32\c72dzwnloader935.ocx.vir
    Let's get some additional info. Please run the MGtools.exe program as specified here:Using MGtools Then attach the requesetd C:\MGlogs.zip file.
     
  21. kevinabrownlee

    kevinabrownlee Private E-2

    mglogs.zip

    log attached
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This log shows that the files and folder you mentioned were not removed by ComboFix; however it also shows that you did not run the DeQuarantine properly. It looks like you did not use notepad to make the CFScript.txt file. You must use note pad. Otherwise you get no line feeds and everything will appear on oneline to ComboFix and it will not restore the files.
     
  23. kevinabrownlee

    kevinabrownlee Private E-2

    heres the file i used

    is it correct, i used notepad each time - If you check it and its ok - do i run it again?
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That appears to be correct. Are you using left click of your mouse to drag the CFScript.txt file ontop of ComboFix.exe? What do you see happen when you do this? Is your antivirus and other protection software shutdown?

    Try the fix in safe boot mode and see what happens.
     
  25. kevinabrownlee

    kevinabrownlee Private E-2

    safe mode

    i tried safe mode, and no change. i dont see the files in the quarantine folder but under that qoobox file there are snapshot data files - could use this snapshot as a restore date
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: safe mode

    Not true. According to your MGlogs.zip file they are there. For example, your My Documents files are list here;

    C:\Qoobox\Quarantine\C\Documents and Settings\Kevin A Brownlee\My Documents

    No! These are just text lists showing file dates, sizes, and MD5 codes.
     
  27. kevinabrownlee

    kevinabrownlee Private E-2

    so any suggestions to get those files to return ??? thanks in advance
     
  28. kevinabrownlee

    kevinabrownlee Private E-2

    and... I looked in the quarantine folder as you pointed out, and I still dont see the missing folders and the corresponding files that were contained within
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They were in you MGlogs.zip file. Let's get a new log and see if they still show. They should all still be there since the DeQuarantine only copies files back. It does not remove them from the Quarantine. If they are missing from the Quarantine it would mean that something else ( a protection program or you ) removed them somehow. If the QooBox folder has been tampered with at all, there will be no way to properly restore the files.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds