View Single Post
Old 02-11-2007, 10:37 AM   #6 (permalink)
fredmh
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


I'm not sure I understand why you stopped Kaspersky as it is reporting 25 viruses and 38 objects but it was stopped before it could
log them. This indicates your system could be seriously infected but I can't tell without the information.

The original file (1417376314.dll) was deleted by ComboFix. If it is coming back, then there is someting in there which is causing it.

Please complete these next steps.


----------------------------------------


Kaspersky - Extended

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect.
    We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

* Turn off the real time scanner of any existing antivirus program while performing the online scan

----------------------------------------

SYSTEM REPAIR ENGINEER

Please download this tool >http://www.kztechs.com/sreng/sreng2.zip]System Repair Engineer


  • Extract it to it's own folder & double click SREng.exe to run it

  • Select 'Smart Scan' & tick "Verify Digital Signatures"

  • Click on the [Scan] button

  • When finished, click on the [Save Reports] button & save the log to Desktop

  • Attach the log in your next reply. Dont post it


Note: You may have to rename SREngLog.log to SREngLog.txt before attaching

----------------------------------------

FOLLOW-UP

Please return and post these items in the order listed:

[b]
Kaspersky scan
SREng log (attached)

Please let me know how your system is behaving.
__________________
fredmh is offline