BleepingComputer.com: Infected system attacks anti-malware software

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Infected system attacks anti-malware software

#1 User is offline   Atreies 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 9
  • Joined: 09-March 11

Posted 09 March 2011 - 06:02 PM

Hi, I have a system that is infected with (most likely) a rootkit. It will not allow any scanners or most antimalware programs to run. So far I have successfully run DDS and gotten a log, gmer but it did not specifically identify any threats, rkill (iexplore version) which finds and kills 2-3 process' but they get recreated instantly and process names change each time. Renaming other scanner's exe's does not work.

What will not run or gets killed shortly after starting: combofix, mbam, superantispyware, hitman pro, catchme, mbr.

Safe mode produces the same results, no obvious bad files created recently, pulling the hard drive and scanning on another pc with mbam, eset and most of the others above does not find any infected files.

Can you provide any further insight? Much appreciation in advance.

#2 User is offline   Budapest 

  • Bleepin' Cynic
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 22,235
  • Joined: 11-November 06
  • Gender:Male

Posted 09 March 2011 - 06:04 PM

Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users