Rootkit(s) and Trojan
Posted on 2009-04-08
I am working on a PC that was infected with Antispyware2009, Cleaner2009, and who knows what else. Sequence of events so far:
Disabled all non MS services and startup items in safe mode
Ran Combofix (Combofix1 log attached)
Ran MBAM with old definitions -- LSP problem and no internet access (MBAM-01 log attached)
Ran MBAM with updates after fixing LSP with WinsockFix (MBAM-02 log attached)
Installed and ran AVG Free
Ran Combofix (Combofix2 log attached)
Ran Hijack This (log attached)
Combofix log is showing hidden files that have not been removed. Need a script or other means to clean them out.
AVG shows asyncmac.sys and atmarpc.sys infected with Trojan Horse Agent_r.G. They are white listed system (network) files and cannot be deleted. I probably can delete and replace them by booting from UBCD4Win CD. Any other methods?