Virus/Malware Preventing ComboFix from running

Posted on 2009-07-14
Medium Priority
Last Modified: 2013-12-06
I am taking a look at a friend's laptop who was complaining that one day several desktop shortcuts appeared out of nowhere and that Windows Defender and AVG popped up with alerts.

My first reaction was to run ComboFix is Safe Mode, however even though it is a fresh download, ComboFix displays a warning that the computer may be infected with a file-patching virus like "Virut".  Malwarebytes found 30 items and removed them, however ComboFix still will not run.

I attempted to run Trend Micro Housecall, however the browser will not navigate to that page, it hangs up on searching for 'search.avg.com'.  Usually ComboFix is my go-to, but if it won't run even in Safe Mode I'm concerned.  Are there are any boot disks that have it pre-installed?

Attached is the HiJackThis log, any input on how to remove this malware would be greatly appreciated.
Question by:Chernesky
LVL 23

Expert Comment

by:Mohamed Osama
ID: 24849731
try renaming combofix first

Author Comment

ID: 24850067
I should have mentioned that in the original post, I always rename ComboFix before running it because I've had problems with viruses recognizing the name before.
LVL 47

Accepted Solution

rpggamergirl earned 2000 total points
ID: 24850069
Have you tried renaming Combofix before saving to your desktop?

Fix these entries in Hijackthis:
R3 - URLSearchHook: (no name) - *{4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)  R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,  O1 - Hosts: advanced-virus-remover2009.com  O1 - Hosts: www.advanced-virus-remover2009.com 

C:\WINDOWS\system32\sdra64.exe <-- and remove this file.

You can also try DrWebCureIt, it's a very tool for detecting and removing virut.
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!


Author Comment

ID: 24850092
I will head over there now to remove those files, expect an update shortly.
LVL 47

Expert Comment

ID: 24850148
Can you acces this link below, use the Combofix instructions there and see if it runs.


Expert Comment

ID: 25320572
Another approach that works sometimes, if renaming doesn't fix the problem,

Start in Safe Mode
- Click/Enter username
-- ASAP, CRTL + ALT + DEL to get the taskbar, even before the desktop loads. This is very important. Any programs that run in the applications list, kill it. If you can kill it quick enough, or even get CF turned on before the rogue program does, it will sometimes allow you to run CF.

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

UPDATE - 6/15/2011 Added support for Release Update 6 Maintenance Patch 2 Point Patch 1 (RU6 MP2 PP1). Fixed a defect in the username field that was hard-coded to look for a specific domain (left over code from testing). This release will be the …
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question