URGENT RE: Current ComboFix Version!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Feb 10, 2009.

  1. AngelsWilliam

    AngelsWilliam Private First Class

    I was running ComboFix as part of your process because my desktop computer began behaving with obvious malware behavior again...

    and when it and MGTools were done running, this mysterious text document called "catchme" appeared on my desktop. I didn't think that could be a good thing, so I went to your forum and did as search and, sure enough, found a post that catchme was malware.

    I followed the instructions in that post (sort of--I didn't download the recommended software, but rather used RegSeeker), deleting all the registry entries that resembled those listed because I didn't have the 001 entries, so I assumed the entries were different for everyone.

    What I did was use the "search the registry" function of RegSeeker and searched for "catchme." 2 of the places it found it was in ComboFix. That was the only place, in fact, that it found catchme.sys. It was not on my computer anywhere.

    Just for the heck of it, I checked my laptop when I got on it this morning because I just recently got done running ComboFix as the routine of working with one of you on ridding the laptop of malware, and the same was true: I had catchme registry entries, and two of them were catchme.sys in ComboFix.

    I don't know what kind of malware "catchme" is, but I can tell you that it is what was causing me to get the message "from Webshots" saying they had detected another program trying to change my default search page. It also popped up a window (and kept popping it up) telling me to type in my password in order to sign into MSN Messenger, which I removed from my computer a LONG time ago. (I had removed Webshots, too, I thought, but there were a bunch of files still there. What's odd is there were only 2 remaining Webshots files on my laptop, and there were 23 on the desktop.)

    Anyway, I thought you should know that the latest ComboFix version has catchme in it. I will be checking my mother (commenterri)'s computer as soon as she comes downstairs and removing it from hers, as well.

    Hope this helps keep other people safe!
    :wave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please leave the malware diagnosis to the experts.;) Catchme has long been part of ComboFix. Catchme is actually part of GMER's rootkit detection software which ComboFix uses. It is not a problem. See http://www.gmer.net/catchme.php for more into. It will also add a load of driver related registry keys referring to catchme.

    And if you got a file like catchme.zip or catchme.txt on your Desktop, it was due to what you did on your own with ComboFix.

    Anytime you run various malware scanner type programs, they may make assumptions about what various setttings on your PC should be set to by default. This is because when something is not set to the Microsoft default, the scanners normally assume that it was changed via malware and thus needs to be set to something that is known to be safe.
     
  3. AngelsWilliam

    AngelsWilliam Private First Class

    What, you mean I'm not an expert after having so much trouble with it in the last year? :p ;) ;) ;)

    Okay, from now on, I promise to be good. :-o

    Take care, hon.
     
  4. AngelsWilliam

    AngelsWilliam Private First Class

    Got an icon for ya, too:

    http://p-userpic.livejournal.com/81503597/13822423

    ("There are 10 types of people in this world. Those who understand binary and those who don't.")
    :wave
    It's made by <lj user=bendybendy>, but she says she doesn't require credit. I always give her credit, anyway, because I make icons, too, and the take effort, just like any other computer graphic. Anyway, thought it might be a fun icon/avatar for you to use somewhere. It's James Marsters as Brainiac in Smallville. I only watched the eps he was in. I do NOT watch Smallville.

    Enjoy,
    Carol
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds