Help with Combofix

Discussion in 'Malware Help (A Specialist Will Reply)' started by LilyLayla, Apr 20, 2008.

  1. LilyLayla

    LilyLayla Private E-2

    Hello,

    Thanks for any help am gonna get here in advance.
    i was trying to post my problem is a thread that has a Similar problem. but i wasnt allowed to, i dont know why.
    but any ways here is my problem.

    i had a malware and without thinking or checking i used combofix just coz i read that i deleted the same malware.

    soo.. it did a backup, did it check and then restared...... but when it restarted the pc it took a long time.. so i restarted it my self and when it started i got this error messege:

    "Windows could not start because the following file is missing or corrupt:
    <Windows root>\system32\hal.dll.
    Please re-install a copy of the above file."


    when i used the HD with that windows i check it and found out where is combofix has the files it backedup..

    can u tell me how to get back these files? how can i restore my pc the way it was from ComboFix backup files?

    i have Windows XP CD and i can run Recovery Console.
    but i get Access is denied" messege..

    so, what can i do?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where and when did you download Combofix? Here? The program had a very bad bug in it a while back, which we believe is now fixed (as of a few weeks ago).

    You can try this:
    1. http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech this often works very well and gets you back to a point with fewer overall changes to your system. That is assuming that the problem is only due to registry corruption.
    2. Then there is a rebuild option. See the below link:
    * http://www.informationweek.com/windows/showArticle.jhtml?articleID=189400897
    * make sure you have the product key available as you will need it at screen 12 (read thru the steps).

    Let us know if either of these help.
     
  3. LilyLayla

    LilyLayla Private E-2

    its not in the registry...
    it deleted folder system32....
    i can see it in its backup folder but in *.dat files..
    how can i extract my system32 files?

    i dont remember where i download it from.. was checking a studied malware and saw someone telling someone to use it in one of the forums and i checked the logs combofix deleted that malware.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If your system 32 folder was removed or items corrupted, I would suggest that you do a repair installation:

    Boot to the xp cd ....let it install files ...choose install new (not Repair _ which would take you to the recovery console) ...hit f8 to the agreement..then when it finds your previous installation..hit "R" for repair...let it rip.
     
  5. LilyLayla

    LilyLayla Private E-2

    hey again...

    well.. i did that and the only choice i had was "L"
    Delete the Windows and install new one in the same folder -.-

    well...
    can u guys tell me how to extract ComboFix backup files?
    my files are there but *.dat
     
  6. LilyLayla

    LilyLayla Private E-2

    just wanted to tell u guys i manged to fix it. and i am using my computer to post this reply...

    i will write down everything happend and what did i do.. in case someone has the same problem... i know its not much but its a small way of saying thanks for trying to help.


    i ran ComboFix and started to do its work, made a restore point and checked everything.
    deleted many things and then it restarted the pc. and while its shutting down to do the restart... i think its stopped so i restarted it by pressing on the restart button.

    it restarted but have this messege:

    "Windows could not start because the following file is missing or corrupt:
    <Windows root>\system32\hal.dll.
    Please re-install a copy of the above file."


    my window's folder system32 was deleted!

    i got my self another HD and installed Windows and got al my info. and while i was checking the old HD i found a "ComboFix" folder and a folder named "QooBox" in the later i found a folder called "Quarantine" in it i found a folder named: "C" in it was a "windows" folder with a "system32" Folder
    the files in it was *.dll.vid

    i was asking for a way to extract my files....

    but then i noticed a folder inside "system32" called ".vir" there i found all the files of the original system32 folder.

    i created a folder in "C:\Windows" directory (my windows) called "system32" and copyed the files to it and guess what, windows started working and combofix competed its task and i get a log am gonna post it here:
     

    Attached Files:

    Last edited by a moderator: Apr 21, 2008
  7. abri

    abri MajorGeek

    Way to go, LilyLayla!!
    Good work!

    There were some problems with one copy of Combofix which was out for only a few hours. I attached your inline log. TimW will look at it and see if there's any malware in among the recovered files.

    abri
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well done!

    There is still a good amount of malware on your system ...Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    Obviously you can skip the ComboFix instructions ...just do the SASpyware log, MalwareBytes log and the MGTools,exe which will produce the MGLogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds