BleepingComputer.com: ComboFix changes folder attributes to hidden

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

ComboFix changes folder attributes to hidden Created a ComboFix folder that duplicated HD repeatedly.

#1 User is offline   AllenRisler 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 12-September 10

Posted 26 June 2011 - 10:10 AM

I have been using ComboFix for several months with no problems. It has been a real life saver at times.
The last view times I used it I noticed that it changed all of the users Documents and Settings to hidden and read only, which has not been to hard to fix, folder, attributes, uncheck hidden, uncheck read only, apply to all files and subfolders.
The last time it used Combo Fix, it did this to the entire C: Drive. I first noticed the problem when I clicked on start, programs, and no programs where showing. Then I noticed that my hard drive capacity had almost no free space. I starting looking for stuff to delete, and found a new CombiFix folder at the root of C:. When I double-clicked on it, I saw the same thing you see when you click on My Computer, so I double-clicked on C:\ComboFix and found that it repeats over and over until it used up all the hard drive capacity.

Edit: Moved topic from Introductions to the more appropriate forum. ~ Animal

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 26 June 2011 - 10:19 AM

No one should be using ComboFix unless specifically instructed to do so by a Malware Removal Expert who can interpret the logs. It is a powerful tool intended by its creator to be "used under the guidance and supervision of an expert. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again. When issues arise with new malware infections or other security tools conflicting with ComboFix, experts are aware of them and can advise users what should or should not be done while providing assistance. Those attempting to use ComboFix on their own do not have such information and are at risk when running the tool in an unsupervised environment. Please read the pinned topic ComboFix usage, Questions, Help? - Look here.

What specific issues are you having that requires using ComboFix?

Compliments of QuietMan7

So with that said, Please follow the instructions in ==>This Guide<==.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include the link to this topic in your new topic and a description of your computer issues and what you have done to resolve them.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

Once you have created the new topic, please reply back here with a link to the new topic.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   AllenRisler 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 12-September 10

Posted 26 June 2011 - 02:48 PM

No that was totally not helpful.

#4 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,238
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 26 June 2011 - 02:56 PM

Hello AllenRisler.

Thank you for bringing this to our attention.

I have contacted the developer and someone will get back with you shortly with further instructions.

For the time being, please minimize any changes you make to the machine.

Thank you,

~Blade
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

#5 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,238
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 26 June 2011 - 03:24 PM

Hello AllenRisler,

Please delete any copies of ComboFix currently on your machine (right click and select Delete); then download a new one from Here

VERY IMPORTANT: Disable all running antivirus, antimalware and firewall programs as they may interfere with the proper running of ComboFix. Click on this link to see a list of programs that should be disabled. NOTE: This list is not all-inclusive. If yours is not listed and you do not know how to disable it, please ask.

Please double click Combofix.exe and follow the onscreen prompts.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


~Blade


In your next reply, please include the following:
ComboFix log

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

#6 User is offline   AllenRisler 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 12-September 10

Posted 27 June 2011 - 02:35 AM

I deleted C:\ComboFix\C:\ComboFix\C:\ComboFix\C:\ComboFix\C:\ComboFix\C:\ComboFix\C:\ComboFix\...
As a first time poster, I was simply providing my usage feedback.
I have no further issue.
Thank you, Blade, for your kind reply.
Please send my regards to the animal with my assurances that I probably won't use ComboFix,
nor recommend it to my friends as I have in the past.

#7 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,238
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 27 June 2011 - 01:41 PM

Ah, I see.

It was my pleasure. :thumbup2:

Since this issue appears to be resolved ... this Topic has been closed.

~Blade
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users