Thread: Possible Threat
View Single Post
Old 08-06-2007, 10:35 PM   #4 (permalink)
forhockey
Analyst, Security Team
 
forhockey's Avatar
 
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,931
OS: Windows 7 Ultimate


Re: Possible Threat

I want to take a closer look at this file.

Download combofix from here

**Save it directly to your desktop**

Open notepad and copy/paste the text in the quotebox below into it:

Code:
http://www.techsupportforum.com/security-center/general-computer-security/172416-possible-threat.html

Suspect::
C:\WINDOWS\system32\WinXpUpdate32.exe
Save this as CFScript




Refering to the picture above, drag CFScript into ComboFix.exe

Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file.
__________________


Proud Member of ASAP
Proud Member of UNITE

Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support.

Donation link for Tech Support Forum
forhockey is offline