Jump to content

Malwarebytes

rootkit issues

- - - - -

2 replies to this topic

#1
EMTI

    New Member

  • Members
  • Pip
  • 1 posts
Hi,

I Got the same problem with one of my customer computer.

What i found, is when we try to open mbam.exe or combofix, or any other program that can help to clean spyware, when you start the scan, the program close automatically, and the spyware / virus reset the security settings on the files used to Everyone. (security tabs on files properties)

If you reset back the security on your files (like mbam.exe) to your account name with full rights (Occurs only on NTFS partition), you are now able to re-execute the software (like mbam.exe). When you restart the scan, oupss, it's not working again and the security reset again to Everyone.

after many hours of triyng everything possible, I try this:

Remove the hard disk from the infected computer.
install the hard drive on a clean computer.
scan the attached hard disk with malware bytes. (dind't found anything)
scan the attached hard disk with kaspersky (dind't found anything)
scan the attached hard disk with SuperAntispyware (didn't found anything)
scan the attached hard disk with nod32 - didn't find anything

for combofix - not try because can't specify a drive letters other than c: to scan

So i will wait until next monday if can find a solution. If can't i will reformat the pc and re-install all the stuff... :)

#2
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

Download and run Win32kDiag:
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Due to the lack of feedback, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us