Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HTTP Malicious RMF File detected


  • Please log in to reply
3 replies to this topic

#1 Wish I was Amish

Wish I was Amish

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:07 AM

Posted 29 August 2011 - 04:35 PM

Symantec Endpoint Protection pops up " [SID: 23793] HTTP Malicious RMF File detected " but it won't remove it. CPU usage is at 100%; svchost.exe using 90+%. Also gives "Generic Host Process for Win32 Services has encountered a problem and needs to close." after it sits idle for a while.

System restore did not resolve the problem. Malware Bytes Anti-Malware found two objects (probably unrelated) and removed them, but the problem persists. ComboFix didn't solve the problem either.

I know Symantec sucks but I work remotely and my company's VPN host-checker requires this exact version. I also just read that you don't recommend ComboFix but I didn't know that when I ran it, and it had worked for me one time a year or so ago when all else failed.

Any help would be greatly appreciated!

BC AdBot (Login to Remove)

 


#2 Wish I was Amish

Wish I was Amish
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:07 AM

Posted 29 August 2011 - 09:19 PM

New notification while sitting idle just now: [SID: 24225] Web Attack: Blackhole Toolkit Website 5 detected

Please help. :(

#3 Wish I was Amish

Wish I was Amish
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:07 AM

Posted 30 August 2011 - 09:02 AM

Ran F-Secure Blacklight Rootkit Eliminator (found nothing) and Sophos Anti-Rootkit (found nothing it recommended for removal).

#4 Wish I was Amish

Wish I was Amish
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:07 AM

Posted 30 August 2011 - 09:59 AM

And now it says "Best Pack ToolKit Website detected"




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users