Thanks for your reply. I can't believe out of all the things I tried, I didn't think to simply change the filenames to confuse it. It was a smart little virus. Anyway, I was able to get MBAM to work, but it only showed up some false positives. Afterwards I got ComboFix to run and it immediately found the rootkit and asked me to reboot before completing the scan. It deleted the following files:
C:\smp.bat
c:\windows\regedit.com
c:\windows\system32\AutoRu
c:\windows\system32\driver
c:\windows\system32\driver
c:\windows\system32\Packet
c:\windows\system32\pthrea
c:\windows\system32\tmp.re
c:\windows\system32\UACbbd
c:\windows\system32\UACbcf
c:\windows\system32\UACewy
c:\windows\system32\uacini
c:\windows\system32\UACsjr
c:\windows\system32\UACuwm
c:\windows\system32\UACviy
c:\windows\system32\UACvpy
c:\windows\system32\UACwex
c:\windows\system32\UACxpt
c:\windows\system32\UACxta
c:\windows\system32\UACylk
c:\windows\system32\WanPac
c:\windows\system32\wpcap.
D:\Autorun.inf
All the UAC files are from the trojan rootkit I mentioned. I'm not entirely sure how this virus works and I was unable to find much information about it online. It blocked a lot of installations though. Thanks again for the suggestion. As far as I can tell the problem is solved. I will play around with it a little bit longer and come back tomorrow to accept your answer.
Main Topics
Browse All Topics





by: rpggamergirlPosted on 2009-03-14 at 20:56:20ID: 23889715
Try deleting that copy of MalwareBytes and Combofix that you already have, then re-download and rename the file before saving them to your desktop. You may have to rename MBAM file twice if it still won't run after installation.
Or if you have access to another pc, download the files into a USB drive and rename before installing into the infected pc.
You need to disable your antivirus shield while running combofix and try not to mouseclick while it's running as it may cause it to stall.
Then show us their logfiles.