05-14-2012 05:18 PM
Found any other .txt logs for Combofix due to previous runs and the quarantine txt are in the folder C:\Qoobox don't touch the other folders inside that folder.
Quads
05-14-2012 05:58 PM
The log is attached.
05-14-2012 06:01 PM
The two text files in C:\Qoobox are attached.
05-14-2012 06:33 PM
That's a little different
Download http://www.pandasecurity.com/enterprise/support/ca
Disable Norton then run the tool.
Quads
05-14-2012 07:44 PM
The panda tool just finished.
Computer is slowing down quite a bit, and startup and shutdown sounds are coming out garbled. How risky is it to keep my computer on for so long? Would I have a better chance of saving it if I just shut it down now and hired a professional in my area to work on it?
05-14-2012 07:55 PM
Where is the Panda log.
the slow down could be because it's trying to find drivers and services that no longer exist, so as that takes resources and everything else slows down including making sounds etc.
Quads
05-14-2012 08:08 PM
Here is the panda log.
05-14-2012 08:22 PM - edited 05-14-2012 08:38 PM
It found the files,
MD5's
B89CFBE8CB247B57D8C10ADAA66B462B https://www.virustotal.com/file/458b56bbbd3cd478e0
MD5 11028C6A84A967070CB1286550F2058F https://www.virustotal.com/file/eeaeb1506d805271b5
Remember you also had or have other program and tool leftovers and maybe it has hurt the netsvcs in the registry to be fixed later if that is so.
You can turn off the PC when you want to as the rootkit appears broken, just some clean up steps to do and checks. I will have to create a script.
Also these tools do take up resouce during the reboot and runnong process as they battle and search for what they need to.
Quads
05-14-2012 08:43 PM
Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Doiwnload the attached CFscript.txt, , For some browsers Right Click the attachment on the forum and select "Save AS" or similar to Download it. See screenshot below.
Now drag the CFScript.txt into the ComboFix.exe

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
05-14-2012 10:36 PM
Stepped away from the computer for a second while ComboFix was running and when I returned the screen was black. It remained black for over 20 minutes, at which time I powered off and powered on again.
No ComboFix log, but there is a "My Computer" icon/link labeled ComboFix on C:\.
Should I run it again?
