Hi! I'm Steve in Ann Arbor Michgian USA.
A first time poster and have been using combofix very successfully on my own, and not really aware of the forum or this community's 'protocol' about using combofix for a few years.
The problem I have run into today is that I have run a removal utility that had found and removed zeroaccess.rootkit from a windows XP SP3 32bit PC.
It appears that I have actually removed the problem as multiple utilities Kaspersky(rescuedisk),Symantec,Webroot,MWB etc. etc. claim it's gone
I have run these other utilities that say the system is clean free & clear however Combofix (and only Combofix) continues to detect and say that it's infected with
the rootkit.
So unless Combofix is somehow superior to all these other utilities in detection of zeroaccess, this seems to be some kind of false positive.
Or my lack of know-how and inability to use this on my own successfully has suddenly kicked in today and I need to ask for help with it.
There is currently no anti-malware software installed or running on the system and background services and processes are at a minimum.
The system seems to work just fine and is very responsive.
More than asking for "help" or for help fixing my individual system I'd prefer to ask & learn how I can get combofix to tell me WHY and HOW it is making this determination.
(is it logging why it thinks this malware is on the system?) and how to I read it.
More than anything really I'm looking for guidance as to how I might be able to better understand WHAT combofix is looking for and detecting when it
is finding and reporting this particular rootkit is present.
By the time I get a response, I'm likely to have already moved on and formated the drive (restored from a backup image), unfortuantely this is a bugger of a problem I can't trust myself that it's truly fixed yet and I'm out of learning time with it.
:-(
Maybe a little shove into the right area of information where I can work myself to become much better with
combofix to the point where I can help others as well as myself a little better than this.
Another issue I've run into recently is that Combofix frequently will detect AVG 2012 on a system that I have carefully removed the software on, all processes files and registry entries
on the systems (AVG is practically gone) yet it still has some *secret* way that it goes out onto the system and determines that AVG is still there.
I'd like to know what it is actually finding to determine this so I can remove it.
(I wonder if it logs enough data to tell me this) by default, or it it can be turned up to show this type of detail.
That's another topic for another day, but just an example to show I'd like to learn how to read the logs and see WHY it is doing or determining things if that's possible.
Thank you for putting up with my LONG intro and asking for more information.
That's 2 of 50 topics I could start aside from the intro :-)
Again.. thanks for tuning in!
Steve
Edit: Moved topic from XP to the more appropriate forum. ~ Animal


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Back to top









