Hit by Combo fix bug...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JD13x, May 24, 2011.

  1. JD13x

    JD13x Private E-2

    The computer boosts up fine. It just sits there after, with allot of CPU usage svchost process in the 20000 range. Internet is unusable do to all the activity that is occurring.....


    I then downloaded and ran Combo fix (suggested by co-worker who works in IT) only to have it quarantine all of my programs.
    I downloaded Rootkit unhooker and ran the reports and it mentioned a possible root kit

    I thought I had the most recent Combofix...

    Then I started reading about the bug it had. I need help restoring them, please?

    I have all the log files, just need to be pointed in the right direction.


    Thanks
     
    Last edited: May 24, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There is a simple fix, I just don't have it. But the good news is, TimW does, and he will log in at some point tomorrow. Thanks for your patience. Don't try and do anything on your own to rectify the problem, just hang in there a little longer. :)
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, JD13x

    This problem with ComboFix was last seem several months ago. How/where did you get the version from that you used?

    Please attach the C:\QooBox\ComboFix-quarantined-files.txt so we can attempt to work up a fix to restore everything. We will need to use ComboFix to restore everything so we will have to restore it to since this bug has deleted ComboFix.exe from the Desktop too (or from where ever it was).

    * Do not attempt to restore anything on your own. Make no more changes to your PC. Just get us the De-Quarantine file so we can make a fix. Also get the ComboFix.exe file out of the Quarantine and back onto your Desktop. If you don't know how to get this file back on to your Desktop, just tell us.

    dr.m
     
  4. JD13x

    JD13x Private E-2

    I couldn't tell where exactly it got it from, but was from an approved beeping computer link or mirror. I thought it was up to date. The computer works, but you can't run any of your programs. Before I could only boot into windows as it was crippled by some infection. I thought I had all of cleared up when I ran malwarebytes.... before I went this route.

    I removed a root years ago from the same computer, but can't for the life of me remember how I did it (I didn't use any programs either).

    I'll post the files when I boot it up tomorrow as it's getting late.

    Thanks
     
  5. JD13x

    JD13x Private E-2

    Here's the reports that I was able to run. I did run OTL as well.
    I hope I have the right log files that you need...
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not attach the Combo quarantine folder. What you attached was a second Add/Remove programs list. Please attach:
    C:\COmboFix.txt
    C:\Qoobox folder --- zipped
     
  7. JD13x

    JD13x Private E-2

    Sorry about that. I had to do some digging as the Combofix.txt file was hidden from view.

    I can't post the C:\Qoobox folder as it's 300+ GB worth of data. Basically it's the entire C drive.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That shows all the files that were removed. You need to go through them all with this form:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DEQUARANTINE::
    C:\Qoobox\Quarantine\C\Documents and Settings\OopsUserProfile [COLOR=DarkRed]<-- folder[/COLOR]
    C:\Qoobox\Quarantine\C\Windows\wpa.dbl.vir [COLOR=DarkRed]<-- virfile[/COLOR]
    
    Quit::
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    You will have to add all of them manually to the above script.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. JD13x

    JD13x Private E-2

    I'm running it now, just waiting for it to generate the combo fix report....

    Fingers crossed.
     
  11. JD13x

    JD13x Private E-2

    It came up with this file.
    All files are still capped with a vir extension.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will just have to go through them all and remove the .vir extension. What other issues are you having, if any?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds