I've followed the readme to the T, need help with ComboFix not rebooting automaticall

Discussion in 'Malware Help (A Specialist Will Reply)' started by fishfreak911, Feb 11, 2012.

  1. fishfreak911

    fishfreak911 Private E-2

    Hello kind sirs. I have been following the read me EXACTLY and got thru 99% of it. Unfortunately, at the end of doing its thing, Combofix told me that it would need to reboot but told me explicitely NOT to reboot manually. I did not ever touch the computer during Combofix's time, and it now appears to have frozen on its own. I see my desktop with 1 of the 40 icons showing and that is where it has left me. I just wanted to make contact before proceeding and screwing something up. All of the steps seem to be getting rid of malware. I have logs for everything when you need it.

    Thanks so much for all you do for us mere mortals.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Manually reboot if you need to. Then please attach the logs that you have so we can check your system.
     
  3. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    ok, so I hard rebooted the PC. Combofix started up automatically and appeared to be doing its think with a small blue window. Next thing I know (about 15 minutes later) there is a black screen with the mouse cursor on it (that was working) but nothing else. I did another hard reboot. Again, Combofix started and did it's thing but this time ended itself ok with a text log file popping up. That file is attached below along with everything else.

    Thanks in advance.
    :wave
     

    Attached Files:

  4. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Here are the RootRepeal logs as well. THANKS!

    BTW, The pooter is acting normal again. Looks good.
     

    Attached Files:

  5. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Strange, I just noticed that I have no sound on my computer now. No other signs of malware at this point which is great.
     
  6. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    I did a little digging and found a yellow exclamation point on SigmaTel High Definition Audio CODEC. I will keep digging.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Sounds like you may have to re-download your audio codecs. In the meantime:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    ClearJavaCache::
    KILLALL::
    File::
    C:\Documents and Settings\Greg Work\Local Settings\Application Data\xk718nh576doxc58655ls68548j36um783n0kp8r6tq661
    C:\Documents and Settings\All Users\Application Data\xk718nh576doxc58655ls68548j36um783n0kp8r6tq661
    C:\Documents and Settings\Greg Work\Templates\xk718nh576doxc58655ls68548j36um783n0kp8r6tq661
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Tim, for some reason, I am now seeing Eset blocking BS web addresses. This is the first time I've seen the errors (coming in at about 2 minutes aparts) since running the clean process.

    I was also having issues with combo fix. I shut disabled Eset like you told me and ran CF. But when I ran CF, it rebooted the laptop, and when it rebooted, Eset reactivated itself, and then CF ran some more. So I don't know if it was able to do its thing.
     

    Attached Files:

  9. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Tim, here are SnagIt pics of the last 2 notices that Eset keeps producing every few minutes....I believe the text info changes slightly with each new attack, but the IP adress is the same for all.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Not everything got removed, so let's do this:

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now go here and run an Eset online scan:
    eSet Online Scan. Attach the log when you are done.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  11. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    K, here are the logs you requested after running the 3 scans you requested.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Looks good. You need to clean out these folders:
    C:\WINDOWS\temp\
    C:\Documents and Settings\Greg Work\Local Settings\temp\

    What malware issues are you still having, if any?
     
  13. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Thank you Tim.

    I tried clearing the folders you mentioned but could not clear them all. See pics attached.

    Also, I am no longer receiving the many Eset warnings, but I am getting the occasional popup window in IE (while sitting on this site) directing me to a CD music sales or game playing website. That has happened twice today, and never before.
     

    Attached Files:

    Last edited: Feb 14, 2012
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Have you cleared out your temp internet cache?
     
  15. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Done as of now. Everything is looking good. I'll give it a few days and def. let you know what happens-good or bad.

    THANKS a million for your help!:wave
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Good to know. Give it some time and then you can do the final clean up:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  17. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    looks like I spoke too soon. I decided to restart for for the heck of it and am getting Eset warnings about the dang Sirefef trojan. that it cannot clean. Also still not able to delete all the temp file data.:-o
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Is it blocking the same IP address?
     
  19. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Yes, I get the first pic avery 2 minutes or so. The second pic only appears on startup.
     

    Attached Files:

  20. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Tim, here is another error I got. Also I am seeing web page redirects that Eset is blocking. Also, this is a new IP address. i've only seen it once, but I keep seeing the old IP address every 2 minutes.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe file and attach the new MGLogs.zip.
     
  22. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Ok, here are all the logs, and an error message that came up while running MGtools. I clicked ok and it finished doing its thing.
     

    Attached Files:

  23. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Hi Tim. FYI-Woke up this morning to a very difficult computer. Windows had restarted to dowload security updates.
    (I don't recall getting the "Object found in memory...Sirefef" error tho, which I usually do) I am getting IE trying to close my MajorGeeks tab, then recovers, then goes to a red off-limits type screen, usually when I refresh. At the same time Eset is stopping attacks with info like these.

    Since I typed this email, things have settled down greatly. I dunno why. Have't had an Eset window in 4+ minutes.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Let's remove some more temp crap:


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  25. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    K, done. I had these Eset errors upon reboot after running Avenger. Hmmmmm, looking pretty good otherwise. I will reboot and see if anything returns. No web page pop ups, redirects or tab recovers as of yet, and no Eset warnings about IP addresses. Getting somewhere now!:-D
     

    Attached Files:

  26. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Was just on Facebook, and this sucker appeared. Grrrrrrrrr I had not rebooted like I said I was going to BTW. Will do now.
     

    Attached Files:

  27. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Hi Tim, I have been putting the laptop thru tests. I only see 1 problem at this point. Upon startup, I keep getting the Sirefef error (one time, and one time only)by Eset, and it says it deletes it. I compared the latest reboot Eset error with the picture from my last post and they are identical. I hope that helps. I feel the end is near for this sucker!
     
  28. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Wow, now I am getting one Eset "address has been blocked" error after another with page redirects and recovered tabs. I haven't done anything other than read a couple of fishing forums, checked Weather.com, and I did download my sound driver from Dell's website. Sound is back and working.

    PLease advise.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Please download Hitman Pro and give it a run.
     
  30. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Ran Hitman, and all seems well. At first, when I saw your reply, the pop ups and redirects were so bad, I couldn't even download the file. It was so bad, I had to reboot. I got a few Eset errors upon bootup, then ran Hitman. It found 2 issues of Sirfef trojan (see attached) and cleaned it upon reboot.

    Thanks Tim.
     

    Attached Files:

    Last edited: Feb 18, 2012
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Good deal. Now tell me if you are still having issues.
     
  32. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Tim, my GOOD FRIEND, thank you. It appears this is one for the books. Case closed! Success!!

    Thank you so much for taking the time to help me. I really do appreciate it!:wave

    You are the Majorest Geek!:major
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  34. fishfreak911

    fishfreak911 Private E-2

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    UPDATE:
    Tim, good morning. I have been using my laptop for a while now and all signs of malware are officially gone!:-D

    Your patience and help really paid off as I was able to use my laptop at a recent show where I needed to run credit cards for sales. So, again, I thank you more than I can say! It is so cool to know that there is someone out there like you willing to help.

    Best Regards, and a Clean Computer,
    Greg
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I've followed the readme to the T, need help with ComboFix not rebooting automati

    Good to know!! ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds