Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Can anyone check this Comofix Log?  Might need a script

Posted on 2010-11-23
8
Medium Priority
?
481 Views
Last Modified: 2013-11-22
Hi All,

We have a Windows XP Pro SP3 machine that seems to have a bad infection.  It gets constant pop-ups and fake AV messages.  Combofix ran and didn't seem to remove it.  Hitmanpro hasn't done much good either.  Working on an MBAM log to post next.  

Would appreciate it if anyone can help review and perhaps get a custom CF script written if needed.

Thanks!
ComboFix.txt
0
Comment
Question by:Jsmply
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 34200970
0
 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 34200979
Also try renaming combofix.exe to something else like cf.com and run it then if that makes any difference.

Sudeep
0
 

Author Comment

by:Jsmply
ID: 34200995
Hi Sudeep, Combofix is able to run but it just doesn't seem to fix the problem.  Can try with a rename anyway.
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 34201055
Also try the TDSSKiller as suggested earlier.

Sudeep
0
 

Author Comment

by:Jsmply
ID: 34201061
Thanks, already running now.  Will post back soon.
0
 

Author Comment

by:Jsmply
ID: 34201125
TDSSKiller says no infection found.  Definitely still there though, getting constant pop-ups from fake AV's, etc.
0
 
LVL 30

Accepted Solution

by:
Sudeep Sharma earned 2000 total points
ID: 34201171
are you able to update the MBAM? If you do them log into safe mode and do the full system scan

Sudeep
0
 

Author Closing Comment

by:Jsmply
ID: 34206715
Well it took multiple passes in MBAM and SAS, along with Combofix and CCleaner, but the machine is now giving a clean result in all scans.  Thx!
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
A new hacking trick has emerged leveraging your own helpdesk or support ticketing tools as an easy way to distribute malware.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question