Jump to content


Photo

New Qoobox folder and catchme in the registry

qoobox catchme Trojans

  • This topic is locked This topic is locked
2 replies to this topic

#1 cad yellow

cad yellow

    Member

  • New Member
  • Pip
  • 1 posts

Posted 06 January 2013 - 12:07 PM

Hello,

I noticed a new folder the other day: C:\Qoobox that has a quarantine and Backenv subfolder. I'm concerned that it's malware and would appreciate your help to find out. 

 

Other info in case it's relevant:

  • I run Norton 360 and Malewarebytes' Anti-Maleware.  I did a full system scan and Norton didn’t find any threats.
  • Autoruns shows a process called catchme that it indicates came from the folder C:\ComboFix\catchme.sys (that no longer exists) and there are catchme folders in the registry.
  • MY OS is Windows 7 Pro and all updates have been applied.
  • I've been having problems booting lately.  The computer runs fine in Safe Mode. I'd been having alot of problems with member disks dropping out of a RAID array so recently broke the RAID. In the process my user profile got corrupted. The boot issues may be associated with remnants of that issue or hardware problems.
  • Norton 360 recently quarantined some Trojans from a few email messages.
  • My PC was recently at repair shop. They may have run some virus tests.

Thanks for your help!



#2 The Dark Knight

The Dark Knight

    Malware Vigilante

  • Trusted Advisor*
  • PipPipPipPipPip
  • 2,214 posts

Posted 06 January 2013 - 03:31 PM

Hello cad yellow. :)

 

Both those folders are from ComboFix. The Backenv folder is still present because most likely ComboFix was not uninstalled correctly.

 

To uninstall ComboFix:

 

Please click Start>Run and copy/paste the following text, including the space between "ComboFix and "/uninstall", into the Run box and click OK:

ComboFix /uninstall


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!

If I have helped you please consider donating to help keep this forum running; see this topic for more details.

unite_zpse83e3a16.gif


#3 The Dark Knight

The Dark Knight

    Malware Vigilante

  • Trusted Advisor*
  • PipPipPipPipPip
  • 2,214 posts

Posted 13 June 2013 - 04:41 PM

Glad we could help. :)

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!

If I have helped you please consider donating to help keep this forum running; see this topic for more details.

unite_zpse83e3a16.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button