I ran Combofix, but when I did, I noticed it taking much longer than normal to run the program (about 4 hours). I knew something was wrong for it taking such a long time, but I was also concerned that if I killed the program while running during mid-process, it might have caused me additional problems, so I let it run it's course.
I was extremely dismayed to see when Combofix had finally finished, my computer was now seriously messed up, as many system, program & personal files & folders were deleted and quarantined. Now most programs wouldn't open or run, shortcuts on my desktop wouldn't work, then Windows Internet Explorer wouldn't open as that folder also became a casualty in this. I then tried using System Restore, but it was unsuccessful.
I got on bleepingcomputers.com website (borrowed another computer to get online), then searched and reviewed the forums regarding this Combofix bug problem. I found several topics on the problem with Combofix like I have, but the most similar in the criteria was "www.bleepingcomputer.com/forums/topic290138.html" (a copy of this topic is below), which basically said this problem can be fixed by downloading and running a special tool designed for this bug called CFDQ-UsrPrf.exe.
Forum posting (topic 290138)
ComboFix problems and resolution for legitimate files being deleted:
Posted 24 January 2010 - 09:41 PM
As many of of you know ComboFix has been pulled due to bug that causes legitimate files to be deleted. For those that have been affected, you would have noticed many deletions taking place as ComboFix was running, and your desktop would be blank. For users of Windows XP, you may still have an Internet Explorer icon and the Recycle Bin still present on your desktop, but everything else would be gone.
To restore the folders and files that were deleted, please download the following file and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe
Now disable all anti-virus program as they may interfere with the restoration process. Instructions on how to do this can be found here. Then launch the CFDQ-UsrPrf.exe program to start the restoration process. When the program has finished your data will have been restored. Please note, that if you had infections located in the deleted folders, these infections will now be restored as well. Therefore please do not reboot without first contacting the helper that was helping you previously as the infections could become active again.
(end).
I ran the CFDQ-UsrPrf.exe. But it restored just a couple of files, the majority were were not touched. I tried running it again, but now was getting an error message: `Error: 0x00007766'.
So then I got the list of program tools outlined in the "Preparation Guide for Use before Requesting Help" needed to download, run and make log files to post.
I needed internet back on my computer, so I copied the quarantined Internet Explorer folder from C:\QooBox and pasted it back into C:\Program Files folder. Then went to that folder in Program Files and I manually removed .VIR extensions on all the files. It worked.
I ran the following: Defogger, DDS and GMER and will attach the log files. Not sure if you want Combofix logs yet or anything else, so I didn't send them until you let me know.
I appreciate your time and expertise towards helping me fix this problem.
DDS (Ver_11-03-05.01) - NTFSx86
Run by owner at 12:14:08.83 on Mon 04/04/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.335 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Documents and Settings\owner\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
mStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
TB: {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {C17590D2-ECB4-4B15-8820-F58798DCC118} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mPolicies-system: DisableCAD = 1 (0x1)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program files\microsoft office\office12\REFIEBAR.DLL
Trusted Zone: google.com\www
Trusted Zone: microsoft.com\catalog.update
Trusted Zone: microsoft.com\office
Trusted Zone: microsoft.com\support
Trusted Zone: microsoft.com\www
Trusted Zone: microsoft.com\www.update
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} -
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
============= SERVICES / DRIVERS ===============
.
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-19 214664]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-4-21 54760]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [2005-1-26 92550]
S3 fsssvc;Windows Live Family Safety Service;"c:\program files\windows live\family safety\fsssvc.exe" --> c:\program files\windows live\family safety\fsssvc.exe [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [2004-4-19 6656]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-19 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-19 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-19 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-19 40552]
S3 WinDefend;Windows Defender;"c:\program files\windows defender\msmpeng.exe" --> c:\program files\windows defender\MsMpEng.exe [?]
.
=============== Created Last 30 ================
.
2011-04-03 10:35:21 -------- d-----w- c:\program files\common files\ODBC
2011-04-03 09:48:29 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-04-03 09:46:54 -------- d-----w- c:\program files\Internet Explorer 1
2011-04-03 05:34:50 -------- d-----w- c:\program files\VideoLAN
2011-03-27 21:55:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-03-27 21:55:48 -------- d-----w- c:\windows\system32\wbem\Repository
2011-03-12 23:11:42 -------- d-----w- C:\MGtools
2011-03-12 23:10:58 660480 ----a-w- C:\CFDQ-UsrPrf.exe
.
==================== Find3M ====================
.
2011-03-10 23:34:23 439808 ----a-w- c:\windows\system32\searchindexer.exe
2011-03-10 23:30:18 1033728 ----a-w- c:\windows\explorer.exe
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-03 01:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2001-08-18 12:00:00 94784 -csh--w- c:\windows\twain.dll
2008-04-14 00:12:07 50688 -csh--w- c:\windows\twain_32.dll
2004-08-20 06:26:54 1216 -csh--w- c:\windows\Twunk_16.dll
2004-08-20 06:26:54 1216 -csh--w- c:\windows\Twunk_32.dll
2008-04-14 00:12:01 57344 --sh--w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12:01 413696 --sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12:02 551936 --sh--w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12:32 11776 --sha-w- c:\windows\system32\regsvr32.exe
.
============= FINISH: 12:16:37.73 ===============
Attached File(s)
-
Attach.txt (15.83K)
Number of downloads: 1 -
ark.txt (712bytes)
Number of downloads: 4

Help
This topic is locked

Back to top










