Skip to content


Reply
Legendary Noble
malwarekiller
Posts: 3,990
Registered: ‎08-08-2011

Re: Another troj z access..

[ Edited ]

OK...can u skip roguekiller and try downloading and running fresh combofix from the URL in my prevous post if it doesnt work try the thing in prevous post.

 

 

 

Delete the current combofix from desktop and download a fresh version from here 

rename combofix to winlogon.exe and then try running it in the below given way.


 

Running Combofix from Run Command

--------------------


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    Go to Posted Image -> Run -> copy/paste in the following single line command into the run box and click OK.


    "%userprofile%\desktop\combofix.exe" /killall



    Posted Image


  • Click OK and this will start ComboFix in a special way.

 

Note:while using this process the desktop may disappear Dont panic! they will return automatically when combofix reboots the machine.

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.
Stone Emissary
shainsaw
Posts: 23
Registered: ‎03-01-2012

Re: Another troj z access..

loaded fresh combo fix, will try it the new way...

Please use plain text.
Legendary Noble
malwarekiller
Posts: 3,990
Registered: ‎08-08-2011

Re: Another troj z access..

sure...this new way...will allow combofix to run without any interrupts...attach the log once done.

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.