This computer appears to be operating normally.
The other computers cannot open task manager or regedit: [process] has been disabled by your administrator.
As stated earlier in this thread, normal "fixes" for those problems have been attempted, but upon reboot, it reverts back to the same problem.
ComboFix finds Bootkit TDL4, infected? tskmgr & regedit not allowed to open
#17
Posted 02 June 2011 - 05:57 PM
On one of the others, I re-ran Combofix, TDSKiller, and MBRCheck, all came back good (except CF with its TDL4 infection).
The workstation still CANNOT run TaskMgr or Regedit.
I installed our latest Symantec Endpoint Protection client on this one, and it popped up with a detection!
Scan type: Auto-Protect Scan
Event: Risk Found!
Security risk detected: W32.SillyDC
File: C:\WINDOWS\system32\gqcj38.dll
Location: C:\WINDOWS\system32
Computer: EASECLASS3
User: SYSTEM
Action taken: Pending Side Effects Analysis : Access denied
Date found: Thursday, June 02, 2011 4:51:02 PM
This was after running the latest ComboFix, TDSKiller, and MBRCheck
-----------
After a reboot, this was cleaned out, and now taskmgr and regedit work.
Is this something new that ComboFix doesn't know about?
The workstation still CANNOT run TaskMgr or Regedit.
I installed our latest Symantec Endpoint Protection client on this one, and it popped up with a detection!
Scan type: Auto-Protect Scan
Event: Risk Found!
Security risk detected: W32.SillyDC
File: C:\WINDOWS\system32\gqcj38.dll
Location: C:\WINDOWS\system32
Computer: EASECLASS3
User: SYSTEM
Action taken: Pending Side Effects Analysis : Access denied
Date found: Thursday, June 02, 2011 4:51:02 PM
This was after running the latest ComboFix, TDSKiller, and MBRCheck
-----------
After a reboot, this was cleaned out, and now taskmgr and regedit work.
Is this something new that ComboFix doesn't know about?
This post has been edited by jonas914: 02 June 2011 - 06:43 PM
#18
Posted 03 June 2011 - 01:09 AM
ComboFix didn't remove it, so it did not detect it.
You can run Malwarebytes on all of them.
If still there will be a problem you need to open a topic for each of them with the logs.
You can run Malwarebytes on all of them.
If still there will be a problem you need to open a topic for each of them with the logs.
#20
Posted 11 June 2011 - 07:45 PM
This thread will now be closed since the issue seems to be resolved.
If you need this topic reopened, please send me a PM and I will reopen it for you. If you should have a new issue, please start a new topic.
Every one else should start a new topic.
If you need this topic reopened, please send me a PM and I will reopen it for you. If you should have a new issue, please start a new topic.
Every one else should start a new topic.

Help
This topic is locked

Back to top









