warturtle, these fles below are legit:
C:\Program Files\desktop.ini
c:\window
Those 2 lock keys are legit so we don't need to worry about them, we could unlock them but since he no longer have combofix won't matter much.
Hi abel,
Besides some .tmp files showing in the log,
there's only a couple of files and services that you could've removed using CFscript but since combofix is no longer installed you can just clean up(empty) your temp folder-> c:\users\Abel\AppData\Loca
and you can also delete these random services pointing to the files in the temp folder, although these services has been stopped(they're not running)
WPYKZCNWPM
YOOQS
So, Kaspersky scan did not find any threats?





by: warturtlePosted on 2009-05-22 at 03:27:33ID: 24449319
Hello Abel,
.framework .jaxer.ser ver.win32_ 1.2.6.0243 13\jam\jax er\nssckbi .dll
roup/mozil la.dev.sec urity/msg/ 0040e1d23f 638661?pli =1
tk.dll l\Temp\WPY KZCNWPM.ex e l\Temp\YOO QS.exe
or MalwareBytes Anti-Malware (www.malwarebytes.org)?? If not, then I suggest downloading one of them and doing a scan with them, they act as a supplement to existing antiviruses. It might be helpful.
I am back ;-). I've seen the ComboFix log and this is what I think might have happened. The only file that ComboFix actually deleted is below:
c:\program files\Eclipse\Eclipse 3.4.1 JEE\plugins\com.aptana.ide
nssckbi.dll is also present in the Mozilla suite, which includes Firefox, ThunderBird, SeaMonkey, etc. So, if you were using Eclipse along with Mozilla suite of products, you might have had a dll conflict possibly.
http://groups.google.com/g
The following files look suspicious from the ComboFix log, could you upload them on www.virustotal.com for a virus check:
C:\32788R22FWJFW.2.tmp
C:\32788R22FWJFW.1.tmp
C:\32788R22FWJFW.0.tmp
C:\Program Files\desktop.ini
c:\windows\SYSTEM32\deploy
c:\users\Abel\AppData\Loca
c:\users\Abel\AppData\Loca
You also have 2 locked registry keys, I am not sure what those keys are meant to do. I need to investigate those, perhaps rpggamergirl can shed some light on it.
Did you scan with SuperAntiSpyware (www.superantispyware.com)
Hope it helps.