Problems w/ ComboFix, Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by btimm, Feb 10, 2010.

  1. btimm

    btimm Private E-2

    Combofix is giving me the message that says "Please allow ComboFix to reboot the machine. WARNING!! Do not manually reboot the machine yourself"

    I was having troubles before with restarting my machine in that I had to do it manually. I am a little concerned to see this message pop and nothing has happened for 20 minutes. Can I restart it myself? It clearly isn't going to do it itself. Any advice would be appreciated.

    Thanks.
     
  2. btimm

    btimm Private E-2

    About 40 minutes now ...
     
  3. btimm

    btimm Private E-2

    It's been about 4 hours now, so it obviously needs to be restarted manually. My question now is what are the ramifications of this action? I figure there must be negative drawbacks from doing this otherwise there would not be a warning. Wil it potentially cause more issues with my computer? Or will it just fail to eliminate the problem it found? Also, is there a particular mode I should restart my computer in, meaning normal mode or safe mode? Thanks.
     
  4. btimm

    btimm Private E-2

    Performed 'READ & RUN ME FIRST', Verification

    I will give a background of my initial situation that caused me to come to this site via a friend referral.

    About a month ago, I got a virus on my computer. I believe it was worm.win32.netsky. It also lead to giving me the Internet Security 2010 virus. I reopened in safe mode, ran malware bytes, ran smitfraudfix.exe, and then the basic Webroot virus sweep. It seemed to work for the time being with one difference. I had to use Google Chrome as a browser, because IE8 freezes when attempting to connect and Firefox flat out won't open. I don't even think it tries to open, because I open task manager (which I had to regain use fo by dleting a registry key that was blocking it) and it doesn't show that it is running or not responding, it just isn't there. Google Chrome migth be acting weird as well, I am not sure since I have never really used it before. But if I do a google search and click on a link, it doesn't bring me to a link, it brings to some popup.

    I went about my business and then it came back once again. It occurred when I went to nfl.com to look up some stats. I did the same thing that I did the first time and it put me back in the same boat with my browsers, but at least my computer was functioning.

    It came back yet another time, and this time it would even load up in safe mode, but I battled through this stupid virus and got it back once again to the same state that I was able to return it to. This time it came from going to a google search and clicking on a link. I honestly don't recall what it was though.

    It returned a fourth time and it was a little more severe this time. The same issues occurred, but When I went to my quarantine in Webroot, I deleted a few files that were there that were malware and shut down the computer. When I tried to restart it to do the process again, it gave me a blue screen with a stop error. Using the OS disk for Windows XP, I was able to use recovery mode and get things situated again to the same spot. This time the site I was trying to access was twoplustwo.com.

    So I sit now with a computer that won't even open Firefox and has weird issues with Google Chrome (although if I remember to open the link a new tab instead of just left licking it, I never get problems). And IE 8 of course just freezes at connect. I figure I have no network connection issues, because as I said, I can open and use Google Chrome. I run malware bytes and perform a virus sweep and it comes back clean. yet I still have these browser issues. I can't help but think that this is tied to the problem. It is not detecting a virus at all, but maybe I have not remedied damage done to the computer or something? Would that make it easier for these pests to return? Or has it never actually left int he first place? It seems they were gone, because I get them when I go to websites right as the page is loading. I am thinking if I can possibly resolve this issue than maybe all f my issues will be resolved. Maybe not, but it is an issue regardless.


    Okay, so I then went and performed the tasks in 'READ & RUN ME FIRST' thread. EVerything ran fairly smoothly except that when I ran ComboFix, it got to the point where it says to not manually reboot the computer and of course my computer did not want to reboot and my hand was forced. I still got a log, so I am not sure if it ran appropriately or not, and I was hoping someone with some experience could take a look and determine if everything is okay now.

    I can get IE8 to work fine now and I uninstalled FireFox when I went through the add/remove programs portion of the thread, because I don't use it anyways, so I do not know if it would work or not now. My guess is it would, because IE8 works fine now. Google Chrome also does not have the issues of bringing popups. However, my computer will not restart or shutdown when I attempt to do so.

    Any comments on these log files or what I can do to ensure my machine is fine now and fix any potential remaining problems would be extremely appreciated. Thanks so much! I can't seem to find my SASlog.txt and Malware Bytes log files for some reason. Do they autosave like the others? Will you need these files given the information I have provided? If so, I can rerun them and manually save the log files and get them to you.

    Thank you for your time, your help is much appreciated!
     

    Attached Files:

  5. btimm

    btimm Private E-2

    I apologize for this thread. I failed to read the bump post before posting and was intending to add information. In any event, I got through the Read & Run section before and made a detailed thread about my situation and will wait patiently for a response. Thank you for yout time, please ignore this thread.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your SAS and latest MBAM logs are here:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\ojvzdisj.xda

    Now tell me exactly what malware issues you are having.
     
  7. btimm

    btimm Private E-2

    TImW, thank you so much for helping me.

    I have attached these files.

    I also went ahead and did what you said concerning the )15 lines and fixed them and also deleted the file you told me to delete in the Application Data directory. Had I not done these things would these issues have just constantly returned?

    Right now, there doesn't seem to be any issues with my computer, with the only exception being that I can't restart or shutdown via the start menu or task manager, I have to do it manually. Through research I have discovered that there is a registry key I can edit that will automatically kill all processes and allow me to restart and shutdown, but with my limited knowledge, that doesn't seem like the best route to take - it seems like a workaround and doesn't fix the problem. Is this related to malware issues like when I wasn't able to open task manager before until I deleted a registry key that was blocking it?

    Thanks again for your help, it is very much appreciated.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what could have affected your ability to shut down properly. I suggest that you post in the software forum for additional assistance with that issue.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds