Solved

Combofix always hangs badly infected Acer Laptop

Posted on 2011-09-29
11
2,399 Views
Last Modified: 2013-11-22
I have an Acer Aspire laptop that has been badly infected by a virus picked up by visiting a malicious website.   Its’s the one where your desktop program shortcuts appear to be missing and there is a program suggesting you activate a windows fix.

Have uninstalled anti-virus software to allow combofix to run

First time Combofix ran, it successfully installed the Recovery Module, then successfully created the restore point but hung after it started to run the 50 virus check stages and never completed the first virus check stage (I left it running for about 8 hours).  There is no disk activity and no response to mouse etc.    Have to switch off by holding in Switch Off key. Have tried to run Combofix with normal user logon, in Safe mode and in Safe Mode with networking but always hangs just after starting the virus check stage.

Have also ran SuperAntispyware which did complete and found a few items to delete.

Any ideas for getting Combofix to run or can someone suggest an alternative cleanup app. I have used Combofix many time in the past with great success.
0
Comment
Question by:ianmal2
11 Comments
 
LVL 7

Expert Comment

by:Christopher Martinez
ID: 36816610
Do you have any CD emulators installed and running? i.e. Daemon, Alcohol 120% etc
0
 
LVL 62

Assisted Solution

by:☠ MASQ ☠
☠ MASQ ☠ earned 200 total points
ID: 36816626
Ideally you need a combination of tools to deal with these.
Have a look at younghv's article here:
http://www.experts-exchange.com/Software/Internet_Email/Anti_Spyware/A_6550-2012-Malware-Variants.html
0
 
LVL 7

Expert Comment

by:karllangston
ID: 36816638
try running something like AVG's boot cd first then move onto things like malwarebytes in normal mode
0
 
LVL 1

Author Comment

by:ianmal2
ID: 36816973
No CD emulators running.  I'll check out the referenced article and AVGs boot CD.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36817073
You could also potentially find the bad files causing the headache if you boot to UBCD/Slave this HDD and use Autoruns, to "Analyze Offline System". It enumerates all the startup locations. They are often very simple to find, in %allusersprofile%\Application Data, or underneath the user's Local Settings\Application Data directories.....

Autoruns
http://live.sysinternals.com/autoruns.exe

Have you also just tried logging in as another user account? Some of these are USER based, and do not affect the entire system.....
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 1

Author Comment

by:ianmal2
ID: 36817279
Yes I have created another user account where everything seems to work normally.  But Combofix still stops at the same point.
0
 
LVL 10

Accepted Solution

by:
Jim-R earned 300 total points
ID: 36817554
rpgamergirl wrote an article specifically on this infection.  Perhaps you could

find your solution within her article here
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36834004
If you could use the Autoruns util under the other account, and hit the Users option at the top, and select the infected user, we should be able to spot the infection.....
0
 
LVL 91

Expert Comment

by:nobus
ID: 36890100
i can recommend mbam; it runs fast and cleans most problems : http://www.malwarebytes.org/mbam.php       
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 36890878
Try deleting that copy and download a new version of ComboFix, if that was a fresh download then it's possible that the file got corrupted so try getting a new one and see if it works.
0
 
LVL 1

Author Comment

by:ianmal2
ID: 36910168
Thanks for all your help.  Just a couple of thing to note. Had to run Kaspersky Virus Removal Tool before TDSSKiller would run.  Found RKill to be more effective that RogueKiller.

And finally even although laptop is now virus free, combofix still won't run?
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
move Windows 10 apps to diff disk 39 144
If XP support has stopped, why am I still getting updates? 3 195
Is CCleaner a virus?  Do you use CCleaner? 18 217
Ransomeware 11 80
Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
Issue: Unstable cursor in Windows XP and Windows runs extremely slow in that any click will bring up the Hour glass (sometimes for several seconds before giving you what you want) . Troubleshooting Process and the FINAL FIX: This issue see…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now