Ran Combo Fix now my files are gone

Discussion in 'Malware Help (A Specialist Will Reply)' started by Carolina68, Jan 24, 2010.

  1. Carolina68

    Carolina68 Private E-2

    I just ran ComboFix and now all my files are gone. I did a system restore and got some of my desktop back, but my files (documents, photos, all my music) are still gone. Can someone help me, please.

    These are my Qoobox quaranteed files.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see this thread if running XP:

    Combo deleted everything..

    Do not attempt to restore anything on your own. Make no more changes to your PC. Just get us the De-Quarantine file so we can make a fix. Also get the ComboFix.exe file out of the Quarantine and back onto your Desktop.
     
    Last edited: Jan 24, 2010
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you been able to place Combo back on your desktop?

    C:\Qoobox\Quarantine\C\Documents and Settings\Nicole Henry\Desktop\ComboFix.exe.vir

    back to

    C:\Documents and Settings\Nicole Henry\Desktop\ComboFix.exe

    Have you now tried doing this fix:

    Now we need to use ComboFix to restore files. This will only restore, it will not delete anything.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, tell us how things are looking. You should check each user account.
     
  4. Carolina68

    Carolina68 Private E-2

    I have followed your instructions. At first the combofix initial screen opened stating it was preparing to scan files, but nothing happened for about 10 minutes and then notepad opened up with the qoobox quarantined files with the blue box at the top saying "DeQuarantine - Notepad".

    some of my icons are starting to reappear, but the notepad file is still open on top, so I assume everything is going ok?

    will i know when it finishes?
     
  5. Carolina68

    Carolina68 Private E-2

    the combofix screen is gone, but the dequarantine-notepad file is still open.
    does that sound correct?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is correct. Attach this dequarantine file to your next message. Also reboot your PC if it has not already rebooted and see how things are working.
     
  7. Carolina68

    Carolina68 Private E-2

    ok, here is a zip file of the dequarantine file

    now I am logging off to reboot.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks good. Let us know how things look after the reboot.

    If you were running the READ & RUN ME cleaning process due to malware problems, you should continue and attach all the requested logs. Do not attempt to run ComboFix again. Currently, it has even been taken offline to avoid additional problems.
     
  9. Carolina68

    Carolina68 Private E-2

    Looks like everything is back....my pictures and my music files are back and working.

    The only thing is when I rebooted, notepad opened twice with the following

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787


    do I just need to close that out or do I need to do something else.

    And thank you so much for your help.....you don't know how much it is appreciated.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just close it.


    Where do your problems with malware stand? Why were you running ComboFix? I'm guessing browser redirects.
     
  11. Carolina68

    Carolina68 Private E-2

    you guessed right.....browser redirects.
    I thought I had everything cleaned up, but malwarebytes keeps intercepting malicious attempts but none of the scans are showing anything so I was running combofix and that's when I lost everything.

    Since all my files are back and working, I am going to wait until tomorrow to try the "read and run me" removal again. Losing all my files was pretty energy draining. One more thing, since Combofix has problems, do i need to delete it and then download it again at a later date?

    I have came here and read these forums before and used a lot of the info I have found, but tonight is the first time I have asked for help and you guys on here go above and beyond. I really can't thank you enough.

    Hopefully I will get through the removal process and get everything cleaned up tomorrow night. Until then.....thanks so much!
     
    Last edited: Jan 24, 2010
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Okay! Let me know if you see the
    Code:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
    
    each time you startup.
     
  13. Carolina68

    Carolina68 Private E-2

    I have did another reboot and the notepad file
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

    did come up again. Is there a simple way to get rid of that?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.

    Navigate to the below file with Windows Explorer:

    C:\Documents and Settings\Administrator.ENAMARIE\Start Menu\Programs\Startup\desktop.ini

    Then right click on it and check the Hidden attribute. Then click Apply and OK.

    Do the same for the below file:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini


    See if it still occurs.
     
  15. Carolina68

    Carolina68 Private E-2

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787


    Ok, did what you said. Instead of it popping up twice on rebooting, it only comes up once now. I double checked to make sure the attributes were set to hidden and they were.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you check both locations? One for the Administrator.ENAMARIE account and one for the All Users account. Both files have to be changed. These are actually two different files.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed that you have two more files to fix the hidden attribute on. Apply the same fix to the below files:

    C:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini
    C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini
     
  18. Carolina68

    Carolina68 Private E-2

    I think I have everything running ok again.....just wanted to ask if I can delete the qoobox folder from my computer?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not until we are sure that everything has been fixed. Since the bug not only removed files and folders, it also messed up some permissions and also the attributes of the desktop.ini files. Let's run the automated fix that was created along with a new version of ComboFix that has removed the bug.

    The below procedure and new tool will automatically fix it and permissions problems.

    Download the new fixed version of combofix.exe and save it to your Desktop. DO NOT RUN IT YET!!! Just make sure you have the new version downloaded and saved.

    Now download this file > http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe


    You should be able to run it from any location but save it to your Desktop if possible. As long as Qoobox has not been tampered with, the tool shall be able to automatically do the below.
    • restore all the required files/folders
    • restore the perms
    • set the correct attributes for desktop.ini
    Now run the CFDQ-UsrPrf.exe program by double clicking on it.
    • Immediately after you run it, YOU MUST NOT reboot your PC. Don't do anything else but continue on with the below..
    • Now immediately run the new version of ComboFix that you saved to your Desktop earlier. This should cause a reboot of your PC after running if malware was detected and removed.
    • After reboot attach the C:\combofix.txt log.
    • Also please run the MGtools.exe program as specified here:Using MGtools Then attach the requesetd C:\MGlogs.zip file
    • (See: HOW TO: Attach Items To Your Post )
    Now tell us how things are working.
    • Do things seem to have been restored?
    • What malware problems are you having?
     
  20. Carolina68

    Carolina68 Private E-2

    ok, thanks. Here is the log files from combofix after running the patch and the new version of combofix.

    everything seems to be running ok.
     

    Attached Files:

    Last edited: Jan 29, 2010
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds