There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop lcd malware memory modem monitor motherboard network printer problem ram registry router slow software sound toshiba trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless xbox
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
LEGACY_CATCHME....catchme.sys

Reply  
Thread Tools
suns2remember's Avatar
Account Disabled with 41 posts.
 
Join Date: Jun 2008
Location: AZ
Experience: Intermediate
22-Jun-2008, 03:24 PM #1
Exclamation LEGACY_CATCHME....catchme.sys
Are these from ComboFix.exe or Files that were found/created by ComboFix.exe??? I thought I deleted ComboFix already by going * Click START then RUN
* Now type Combofix /u in the runbox and click OK.

I run the MBAM and "IT" never found both (
Application.NirCmd & Trojan.Generic)

I was very curious why Spyware Doctor found it and not the latest version MBAM (1.18) because its a KEYLOGGER.

Application.NirCmd (15 Infections)


Registry Value

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Combofix_wow

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Runs

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware, Snapshot

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME, Next Instance

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Service

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Legacy

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, ConfigFlags

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Class

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, ClassGUID

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, DeviceDesc

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000, Capabilities


Registry Key

- HKEY_LOCAL_MACHINE\SOFTWARE\Swearware

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME\0000

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\
LEGACY_CATCHME


Folder

C:\ComboFix



And it also found Trojan.Generic in the registry key:


HKEY_USERS\S-1-5-21-4083679094-547138833-3963966-1008\
Software\W get
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:20 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.