Posted 25 August 2009 - 10:00 PM
This computer has an infection that seems to recognize all detection/removal tools, and it is not tricked by renaming files like combofix.exe -> random.exe
Craziest thing about it is that if I rename something like hijackthis, it will run for a moment, then the virus recognizes it, kills it, and won't let me open the file again. It learns to block the filenames - a windows error comes up with something like "cannot find the specified path or file" once the virus knows what I have renamed it to.
I was handed a laptop that was getting to the welcome screen, playing the windows startup sound, and then just sitting there with a blue screen. I found that task manager worked, and i was able to run tasks using it. I can get to websites using the address bar in iexplore, but noticed google search result links were all being redirected. So I knew there was an infection.
I have tried:
combofix- when renamed to something like "abcd.exe" the little combofix loading box shows up, but when the command prompt window should appear, the program closes.
hijackthis - when renamed, hjt starts, but as soon as I start a system scan, it closes. If I try to open the renamed file again, windows says it cannot find it.
malwarebytes antimalware - i renamed the installer file, installed it to a renamed directory, renamed the executable, but it would not open. Instantly killed.
mgtools - same general idea
superantispyware - same
sdfix, smitfraudfix - same
rootrepeal - same
I gave up on this for the time being, went to online scans - pc cillin, and one other - both of them gave me errors when they tried to scan.
I tried searching for all files created in the windows folder in the last day, deleted all suspicious files. Noted that braviax.exe kept coming back.
Tried removing all registry entries related to braviax, also noticed that winlogon shell entrie had some other stuff after "explorer.exe" so i removed that stuff.
Still no luck running any scans, no luck fixing anything.
I just now saw a link for RegistrarLite but don't have the computer again until tomorrow - has anyone had any luck with this?
Or does anyone have any other ideas? Thanks in advance.
Edit: Moved topic from XP to the more appropriate forum. ~ Animal