Macafee keeps Deleting Combofix

Experts -

I've been working on a PC here, it has macafee, and obviously has some rootkit activity going on. I ran Malwarebytes to the point of no result, but the problem keeps comming back, i'm sure its a rootkit. I normally use combofix, the problem is, macafee keeps deleting it each time i run it. I cannot find a way to disable macafee and allow it to run, any ideas?
LVL 2
STS-TechAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
CluskittConnect With a Mentor Commented:
Ah, so that is your problem. DEP is seeing combofix as a threat. Check this: http://support.microsoft.com/kb/875352
0
 
CluskittCommented:
In the AV options, there is always an exclude list. Just create a new folder, add it to the exclude list, then copy combofix there.

Alternately, you could simply stop AV services and run combofix. You could also simply run in safe mode and do the same.
0
 
STS-TechAuthor Commented:
Clus - I've tried safe mode, and disabling the services via msconfig, but mcafee will still start. I'm looking for a way to exclude files and folder, but i can't find any option for this in mcafee
0
NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

 
CluskittCommented:
Safe mode shouldn't load AV. Safe mode only loads essential drivers and services. Sounds to me like you have McAfee infected. In your case, I would probably use a Live CD.
0
 
STS-TechAuthor Commented:
Not to be bothersome, but every computer i've worked on with macafee, norton, and kaspersky loads the anti-virus is safe mode.

I think i will need to uninstall mcafee
0
 
zsaurabhCommented:
Go to servies.msc and stop the Mcafee services then run Combofix
0
 
STS-TechAuthor Commented:
disabling services did not work, i cannot disable real time scan service, which could be the problem
0
 
zsaurabhCommented:
Check the registry...

HKEY_LOCAL_MACHINE\SOFTWARE\McAfee  
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McAfeeFramework
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McShield

see if you have permissions on these folders

Give permission to yourself and Stop/pause the Mcafee services
0
 
STS-TechAuthor Commented:
Ok well i removed mcafee, and the file is still being deleted, i've renamed, redownlaoded, ran malwarebytes, rkill, smitfraud fix, but combo fix jsut keeps getting deleted, any ideas?
0
 
zsaurabhCommented:
Do you have any other Antivirus running?
0
 
CluskittCommented:
Most likely, your rootkit is what's deleting the file. A live CD would be your best option (or a rescue CD).
0
 
STS-TechAuthor Commented:
No i do not
0
 
CluskittCommented:
Or removing the hard drive and plugging it to another PC as a slave.
0
 
STS-TechAuthor Commented:
Clus - any good ideas for a rescue cd? I know i have an ultimate boot cd somewhere around here that has avira rescue
0
 
CluskittCommented:
If you have a good AV in a nearby computer, use that one.
We use CA eTrust in our company. I, myself, have always been a bit partial to Nod32. It's your choice, really. But, for this, don't go with a free version. They're not worth it for cleaning infections. They're just reasonable in preventing them.
0
 
STS-TechAuthor Commented:
ok i'll run a KAV scan on it after my GMER scan finishes
0
 
CluskittCommented:
Alternatively, you could use a Linux CD, like I suggested, then run ComboFix on WINE. Or run a Windows live CD.
0
 
optomaCommented:
Run TdssKiller and Hitmanpro.
http://support.kaspersky.com/viruses/solutions?qid=208280684
http://www.surfright.nl/en/hitmanpro

Also try Combofix  again but rename it prior to saving it to desktop
0
 
STS-TechAuthor Commented:
GMER found a bad service, i was unable to delete it so i disabled it so i could delete it next go around. When i rebooted GMER found nothing. I tried running combo fix and it was still deleted. I then tried to use the KAV rescue CD which would not boot. Next i tried AVIRA, it just finished and found no results. Any other ideas? I can still slave it and run KAV on the drive, but atm i have another drive hooked up to that PC.

Any other ideas?
0
 
flubbsterCommented:
Open the registry and navigate to here:

HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

Scroll down through that key and look for any entries that have combofix. If found, delete them. If you like, select the entry and look on the right side of the screen to see what the entry is set for. If it exists, I bet it is deleting it on execution. Entries in this key remap applications to another function, redirect them, or can delete them as you are seeing.
0
 
CluskittCommented:
If you had found out the infection name, it would be a good idea to run a removal tool for it. Other than that, however, I don't think you need to do anything more. Your system seems to be clean, though I would rerun Malware Bytes, just to be sure.
0
 
STS-TechAuthor Commented:
Flub - I see nothing for combo fix in that area.

Clus - I wish i had written it down, dumbass mistake. I feel that something has to be afecting it still to keep deleting combo fix as soon as it runs.
0
 
CluskittCommented:
Did you try changing the exe name, as suggested?
0
 
STS-TechAuthor Commented:
Yes, i did multiple times, that was my first method to troubleshoot.
0
 
CluskittCommented:
Is this the only exe this happens with? Have you tried the exact same file in another PC? Or scan the file in another PC?
0
 
CluskittCommented:
Also, what if you try to download it from their site and run that one?
0
 
STS-TechAuthor Commented:
Yes it is the only EXE, mbam is fine, smit fraud fix, gmer, rkill, anything i throw at it is fine, just combo fix. I'll try a new exe and report back
0
 
STS-TechAuthor Commented:
WEll guess what? It worked! I downloaded it, renamed it, and it ran. Its running now, i received a popup though, from DATA EXECUTION PREVENTION, it says it closed the program, but combo fix is still running, any ideas?
0
 
optomaCommented:
Post CFs log when completed. No harm to run the other scanners
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.