Jump to content
Posted 04 December 2013 - 05:00 PM
Posted 04 December 2013 - 06:36 PM
Screenshot of exactly what you are referring to?
Note that ComboFix is a tool used for neutralizing malware...not for "cleanup" of any other sort. If you have a system problem stemming from your use of ComboFix to deal with malware...you really should post your ComboFix log in the appropriate forum for dealing with Malware...and allow persons knowledgeable about malware and ComboFix to express their opinions. IMO, such is not an issue for the XP forum, since ComboFix usage and analysis is beyond the scope of "XP issues."
Note that the forum for posting malware logs...is the same forum reflecting the Prep Guide, not any other forum here at BC.
Thanks for understanding .
Posted 05 December 2013 - 12:00 AM
This is what ComboFix does
"ComboFix is a program, created by sUBs, that scans your computer for known malware, and when found, attempts to clean these infections automatically. In addition to being able to remove a large amount of the most common and current malware, ComboFix also displays a report that can be used by trained helpers to remove malware that is not automatically removed by the program."
use autorun and check if u can see the strange logon notify box with crazy ascii characters in it. if u do u can deleted from the startup
Posted 05 December 2013 - 08:27 AM
Posted 05 December 2013 - 11:20 AM
Posted 05 December 2013 - 11:34 AM
So I have found multiple forums regarding to this issue it seems that these people had used gmer, and some other tools here are the links to the forums.
No one has been able to figure this out and it seems to be related to one of the tools either changing a registry entry or something.
I also have the combofix log do you want it in this forum?
Posted 05 December 2013 - 11:46 AM
Posted 05 December 2013 - 06:16 PM
Just to add FYI or if others are interested these links are all 4 to 6 years old. Not current=>
06-29-2009 Tech Support Forum
6 years ago TechRepublic community
08-09-09 MajorGeeks Support Forums
At times there has been a bad version of ComboFix released, but it is removed ASAP.
Thank you -
Posted 05 December 2013 - 06:48 PM
I have been reading the CF discussion topics here and at TSF since before those topics were posted and I don't recall anything about CF being responsible for such an issue. That doesn't mean its not the cause in this case with the current version which is why further investigation is needed.
Posted 06 December 2013 - 02:34 PM
Ok this Is the Fix I was looking for!!
its old but worked!
Posted 06 December 2013 - 02:36 PM
seems to be something that is being removed (by combofix) out of the registry when malware infects it. Only does this in xp and has done it maybe 4 times on different xp computers over the last 9 months
maybe this fix will help you guys out.
Thnx again folks for your time in this.
Edited by Redplauge, 06 December 2013 - 02:37 PM.
Posted 06 December 2013 - 04:03 PM
I don't know what exactly happened, but all I know is.. The most common values in the registry which are responsible for a message at Windows Logon (Logon banners) are next values:
LegalNoticeCaption = "The caption text"
LegalNoticeText = "The body of the banner"
They are present under the "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon" key.
And, they may be present under the "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system" - key in the registry.
And that's what we have done now.. we cleared out those values.
Posted 06 December 2013 - 04:20 PM
lol way back machine, "Google" actually found it because of the search words. But yes it did work, thnx again.
Posted 06 December 2013 - 07:37 PM
I did note the Service pack was only SP2 on the linked fix -
>> Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) <<
Leading me to think that the issue may occur on a machine that is not fully updated ??
You must remember that sUBs works on fully updated systems when updating his tool.
Please check that the Service Pack is 3 and all other updates are fully installed -
Also I have just installed / run / diagnosed a ComboFix log on a Fully Updated / XP SP3 based system (without problems).
Note : I do know the program is updated often, and old versions need to be deleted for these reasons.
Just a few random thoughts -
0 members, 0 guests, 0 anonymous users