Post the log
Here it is:
Sophos Anti-Rootkit Version 1.5.0 © 2009 Sophos Plc
Started logging on 8/18/2009 at 15:43:41 PM
User "Jenny" on computer "MAMA"
Windows version 5.1 SP 3.0 Service Pack 3 build 2600 SM=0x300 PT=0x1 Win32
Info: Starting process scan.
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Program Files\mbam\zztoy.com
Hidden: file C:\WINDOWS\system32\hkcmd.exe
Hidden: file C:\WINDOWS\system32\igfxtray.exe
Hidden: file C:\WINDOWS\foo
Hidden: file C:\sas\SUPERAntiSpyware.exe
Hidden: file C:\Program Files\mbam\winlogon.exe
Hidden: file C:\sasII\sas.exe
Hidden: file C:\hjt\llll.com
Hidden: file C:\WINDOWS\$NtUninstallKB828035_RTM$\wkssvc.dll
Hidden: file C:\WINDOWS\$NtUninstallKB828035_RTM$\msgsvc.dll
Hidden: file C:\WINDOWS\$NtUninstallKB824141_RTM$\user32.dll
Hidden: file C:\WINDOWS\$NtUninstallKB824141_RTM$\win32k.sys
Hidden: file C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll
Hidden: file C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll
Hidden: file C:\WINDOWS\$NtUninstallKB824141$\user32.dll
Hidden: file C:\WINDOWS\$NtUninstallKB824141$\win32k.sys
Hidden: file C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx
Hidden: file C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll
Hidden: file C:\auto\aa.exe
Hidden: file C:\WINDOWS\system32\MRT.exe
Info: Starting disk scan of E: (FAT).
Stopped logging on 8/18/2009 at 17:15:04 PM
Edit to add:
In case it's not entirely obvious:
C:\Program Files\mbam\zztoy.com
C:\Program Files\mbam\winlogon.exe
C:\sas\SUPERAntiSpyware.exe
C:\sasII\sas.exe
C:\hjt\llll.com
were my attempts at renaming malwarebytes, superantispyware and hijackthis executables to run while the virus was active.
Also: not understanding why they are identified as hidden files, because I can see them with a regular "dir" command from the prompt...
Edited by thesamim, 18 August 2009 - 11:08 PM.