ComboFix problems and resolution for legitimate files being deleted This is from 1/24/10
#1
Posted 24 January 2010 - 11:41 PM
To restore the folders and files that were deleted, please download the following file and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe
Now disable all anti-virus program as they may interfere with the restoration process. Instructions on how to do this can be found here. Then launch the CFDQ-UsrPrf.exe program to start the restoration process. When the program has finished your data will have been restored. Please note, that if you had infections located in the deleted folders, these infections will now be restored as well. Therefore please do not reboot without first contacting the helper that was helping you previously as the infections could become active again.
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#2
Posted 25 January 2010 - 03:04 AM
That's where I am now, post-restore point. But most of my programs appear to be gone again. Strangely, Word, PDF, and Text documents, as well as picture files, all appear on my desktop and in the 'My Documents' or 'My Pictures' folder as they should. Other programs don't, but I know they are working because I can go into 'My Computer', then 'Program Files' and excess everything I use to be able to. It's just that I can't see almost anything apart from what I mentioned on my desktop or by going to 'Start' and the 'Programs'. Did I do something wrong? Should I undo the restore point and try to regain the permissions another way? Oh, and I have the internet back now since I did the SystemRestore, obviously.
Edit: I ran the batch file too, but i'm not sure if it did anything. A black popup window appeared for a few seconds with some text in it, and then was gone before I could read it. Nothing else appeared to be happening, so I restarted the computer and everything appears as I just described.
Edit again: Ok, I know i'm probably going to drive yall, nuts, but just for the sake of being thorough, I should also note that one of things I once again can't see when I click 'Start' then 'Programs' is Accessories, so i'm not sure how to get into System Restore again if I need to.
This post has been edited by y2roby: 25 January 2010 - 03:36 AM
#3
Posted 25 January 2010 - 08:01 AM
BTW, for the Author's info, Combo deleted the DELL System Restore on the first pass, so I cannot proceed with that when, and if, ComboFix ever stops.
Oh, and to y2roby, if you want to start System Restore, start it from "Help & Support", if it still exists in your start menu.
EDIT: CF now finished, restarted to desktop, everything seems to be fine...have not run the desktop.bat file as yet, just checking out state at the moment, will re-edit if any further problems arise..
FURTHER EDIT: This sounds strange but, I know Win XP SP3 was installed on machine, now its SP2..strange indeed....
This post has been edited by Browne: 25 January 2010 - 09:36 AM
#4
Posted 25 January 2010 - 09:44 AM
I did the thing with cfscript, after altering it for d drive and d folder (i ran combofix on d drive)and it restored many of the files that it had deleted, but others it did not. It didn't restore my computers ability to connect to internet, and a few other things are still askew, like programs menu, and other things. I was hoping there was something else I could do.
EDIT: I just want to clarify that most of my media files and word documents were restored, and I can fish the few remaining out of the qoobox folder. It's just that I can't connect to the internet, and my programs menu is skewed, really. I can deal with the programs menu issue, but trying to get back on the internet is the main issue. I'm kind of scared to run the exe file you have posted, as I already did the thing with cfscript.
This post has been edited by bigpinkears: 25 January 2010 - 10:04 AM
#5
Posted 25 January 2010 - 10:00 AM
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#7
Posted 25 January 2010 - 10:40 AM
Grinler, on Jan 25 2010, 04:00 PM, said:
After running the script file, I THINK all has been restored. Should I now run the .exe file? And if so, what will that do to the files already restored?
#8
Posted 25 January 2010 - 01:12 PM
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#9
Posted 25 January 2010 - 01:17 PM
I saw a few logs that I saw in the Malware Removal forum that I saw with some users not aware of this tool to dequarantine what has been removed. Is it possible to have a pinned topic there regarding this as well so user's are aware? Just a suggestion.
With Regards,
Extremeboy
If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.
The help you receive here is always free but if you wish to show your appreciation, you may wish to
.
#10
Posted 25 January 2010 - 01:18 PM
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#11
Posted 25 January 2010 - 01:21 PM
If I find anymore, I'll refer them to this thread until an announcement is made of this.
With Regards,
Extremeboy
If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.
The help you receive here is always free but if you wish to show your appreciation, you may wish to
.
#12
Posted 25 January 2010 - 01:51 PM
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#13
Posted 25 January 2010 - 02:10 PM
#14
Posted 25 January 2010 - 02:36 PM
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#15
Posted 25 January 2010 - 03:19 PM
I mean...won't the same thing happen all over again if I run the latest version of Combofix? I have an older version which I suppose is safe.
I understand it’s hard for developers to perfect this program but I'm kind of confused as to why the DL link is removed from the website, yet Combofix updates for those who have the actual .exe, to a version which wipes personal files?
Thanks for the quick solution though

Help



Back to top










