View Single Post
Old 08-20-2008, 06:04 AM   #24 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,450
OS: XP SP3


Re: heur trojan mess - Cannot Update OS - SP3 cannot find CLBCATQ dll's

Hi,

Quote:
Also, I noticed that during cfscript/combofix there was a warning - WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED. I recall you instructed me to install the console but, when I dragged and dropped the Microsoft Recovery Console download onto ComboFix, an error - c\windows\system32 attrib.exe is not a valid Win32 application - was reported. Just a reminder, so in my next post when you see the cfscript.txt/combofix report, you will see the warning above.
Attrib.exe was present in your system. I'm not sure what's causing that error and I am trying to find out.

Quote:
I searched for the file above (searched c: drive for attrib) and found the follwoing instances:

c:\327882R2FWJFW - Attribcf.exe
c:\combofix - Attribcf.exe
c:\windows\I386 - attrib.ex_
c:\windows\system32 - attrib.exe
c:\windows\system32\dllcache - attrib.exe
If you haven't run Combofix yet, make sure that your teatimer and AVG are still disabled when you're running Combofix. Please try placing Combofix.exe, the Microsoft Recovery Console package, and the CFScript.txt at the root of the drive (C:\) and do the drag and drop there. Install the recovery package first. When you receive the The Recovery Console was successfully installed message, please continue as follows:



Click No to exit. Go to the root of the Drive (C:\) again and drag CFScript.txt into ComboFix.exe. Follow the prompts and post the log please.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline