There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer black screen boot computer connection crash css dell display driver drivers email error ethernet excel explorer firefox firefox 3 game hard drive internet internet explorer itunes laptop lcd linux malware monitor network networking nvidia outlook outlook 2003 outlook express partition password printer problem router slow software sound trojan usb video virus vista windows windows xp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
LEGACY_CATCHME....catchme.sys


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
suns2remember's Avatar
Account Disabled with 41 posts.
 
Join Date: Jun 2008
Location: AZ
Experience: Intermediate
22-Jun-2008, 02:24 PM #1
Exclamation LEGACY_CATCHME....catchme.sys
Are these from ComboFix.exe or Files that were found/created by ComboFix.exe??? I thought I deleted ComboFix already by going * Click START then RUN
* Now type Combofix /u in the runbox and click OK.

I run the MBAM and "IT" never found both (
Application.NirCmd & Trojan.Generic)

I was very curious why Spyware Doctor found it and not the latest version MBAM (1.18) because its a KEYLOGGER.

Application.NirCmd (15 Infections)


Registry Value

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Combofix_wow

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Runs

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Snapshot

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME, Next Instance

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Service

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Legacy

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, ConfigFlags

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Class

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, ClassGUID

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, DeviceDesc

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Capabilities


Registry Key

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME


Folder

C:\ComboFix



And it also found Trojan.Generic in the registry key:


HKEY_USERS\S-1-5-21-4083679094-547138833-3963966-1008\
Software\W get
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 04:21 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.