Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 4th September 2006   #1
Inactive
 
Profile:
Join Date: Jan 2002
Location: Albuquerque, NM, USA
Posts: 5,747
Computer Experience:
still learning
Welshjim Reputation Level


TeMerc--Any page where I can read what combofix.exe does? I can find no description on bleedingcomputer, though I see that a fellow named "sUBs" wrote it.
Welshjim is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 4th September 2006   #2
SuperGeek
 
TeMerc's Avatar
 
Profile:
Join Date: May 2006
Location: PHX. AZ
Posts: 3,311
Computer Experience:
Intermediate
TeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation Level


Quote:
Originally Posted by Welshjim
TeMerc--Any page where I can read what combofix.exe does? I can find no description on bleedingcomputer, though I see that a fellow named "sUBs" wrote it.
ComboFix specifically targets SurfSideKick, QooLogic, Look2Me or any combination of that group.

It also nicely picks out Vundo infections and clears some, but not all.

One of the better things it does is pick files recently created which can give clues to other infections. It's very robust too. You can use it to unhook any dll in the system32 folder. You can use it to delete up to as many as 8 files using its command line functions.

It deletes a bunch of files related to the infections above automatically and is updated fairly regularly.

There is more but that's it in a nutshell.

TeMerc is offline   Reply With Quote
Old 4th September 2006   #3
Inactive
 
Profile:
Join Date: Jan 2002
Location: Albuquerque, NM, USA
Posts: 5,747
Computer Experience:
still learning
Welshjim Reputation Level


TeMerc--Thanks. I understand that combofix.exe does not run if I click on it, but rather offers some options, help, etc. about what to do next. I had assumed that clicking on combofix.exe would have it take action, without telling what was going on.
Welshjim is offline   Reply With Quote
Old 4th September 2006   #4
SuperGeek
 
TeMerc's Avatar
 
Profile:
Join Date: May 2006
Location: PHX. AZ
Posts: 3,311
Computer Experience:
Intermediate
TeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation Level


Quote:
Originally Posted by Welshjim
TeMerc--Thanks. I understand that combofix.exe does not run if I click on it, but rather offers some options, help, etc. about what to do next. I had assumed that clicking on combofix.exe would have it take action, without telling what was going on.
Jim I split this off the users HJT analysis, no need to clutter things up on them.

You should run ComboFix on your machine, it will cause no ill effects, it just scans and looks for specific files\folders. All the ones targeted are malware, it does not reply on any type of heuristics, so it's highly unlikely, if not impossible to remove something automatically.

There is even a list of files\folders it currently targets.

TeMerc is offline   Reply With Quote
Old 5th September 2006   #5
WindowsBBS Team Member
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,640
Computer Experience:
Often it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi Jim
I'm wondering the same.
Where I'm going to school, They don't use it as yet. I have a question posted to them.
It seems like a very extensive tool. I would like to know how to read it. except for the little I have picked up from TeMerc using it. I know nothing about it

I ran it on my machine, Didn't see anything that looked suspicious

Geri


Last edited by Geri; 5th September 2006 at 05:21.
Geri is offline   Reply With Quote
Old 5th September 2006   #6
SuperGeek
 
TeMerc's Avatar
 
Profile:
Join Date: May 2006
Location: PHX. AZ
Posts: 3,311
Computer Experience:
Intermediate
TeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation Level


Maybe I'll ask the devekoper if he has any other tuts in other schools. I know the biggest one is over at SWI Boot Camp. Didn't notice anything at MRU or G2G, but also didn't really look.

Or maybe I'll ask him if I can copy some of the basics about it. It really makes no sense that other schools wouldn't have it to be used.

TeMerc is offline   Reply With Quote



Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Removal Trojan Downloader Generic HGT etc. LarryB227 Malware and Virus Removal 37 1st September 2006 21:40
New HJT log for TeMerc... tork30 Malware and Virus Removal 38 28th August 2006 06:57
2nd user on Dell Dimension 2400 cpumedic Malware and Virus Removal 9 26th July 2006 18:34


All times are GMT +1. The time now is 08:17.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1
Copyright © 2002 - 2010 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]