
04-15-2012 06:27 AM
I should add, it won't let me reload it because it is alread there. What was odd was when I went to combofix on my hard drive, all that was there under that heading was a replication of my hard drive. This is from my other computer, so I have not turned it on again since.
Thank you again!
04-15-2012 07:25 AM - edited 04-15-2012 07:26 AM
OK...lets get the other way round of this
Download AVPTool from Here to your desktop
(You have to enter your e-mail address and click on Submit Form button. Please download latest English version of this tool)
Run the programme you have just downloaded to your desktop (it will be randomly named )
First we will run a virus scan
Click the cog in the upper right 
Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan
(Please be patient as this scan can take a few hours)
Allow AVP to disinfect all infections found
Once it has finished select report tab (last tab)
Select Detected threats report from the left and press Save button
Save it to your desktop and attach to your next post
Now the Analysis
Rerun VRT and select the Manual Disinfection tab and press Start Gathering System Information 
On completion click the link to locate the zip file to upload and attach to your next post 
04-15-2012 10:15 AM
Thank you. I just started this Kaspersky tool. Do I need to remove the Combofix program once done? If so, how do I do it?
Thanks again.
04-15-2012 03:16 PM
Just an update, the Kaspersky software is still scanning, and it appears it will be a few more hours before it is done.
04-15-2012 06:44 PM
Update - this is showing that it is only 43% done so far, still in Outlook going through emails, but only one object found so far. It is showing 10 hours to go still, which I hope changes onceit completes scanning outlook.
04-16-2012 12:12 AM - edited 04-16-2012 12:27 AM
Keep patience! it takes long time.let combofix stay there for now.
04-16-2012 02:45 AM
OK - the initial scan is over (finally), one threat detected and quarantined. Report attached. Starting part 2 now.
04-16-2012
03:03 AM
- last edited on
04-16-2012
06:08 AM
by
ornahp
And
[mod note: .zip file removed. please do not post .zip/.exe files]
04-16-2012 03:07 AM - edited 04-16-2012 03:09 AM
nothing malicious in there really...try deeting current combofix from the desktop and download and run a fresh version from the given URL
04-16-2012 03:26 AM
Trying now. I will keep you updated.
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
