New infection, seemingly undetectable

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nexworks, Oct 8, 2009.

  1. Nexworks

    Nexworks Private E-2

    Let me start off by saying that I dont have any logs for you all as both infected systems from last week and this week I ended up wiping and reinstalling. However the infection im running into automatically closes all malware detecting/removal software I try to run including Autoruns and Hijackthis. Process Explorer is allowed to run but it does not see anything. Ive snagged RootRepeal from this site and will try it the next time I see it however given the fact that I cannot see any new or modified files on the system when viewed externally through BartPE, it is likely the infections are rootkits that are hidding inside existing windows files. System restore and even a manual rollback of the registry does not affect these infections. So that said, short of reinstalling windows every time I run into this bugger, what else can I try to get rid of them? Is there any way of running Autoruns in a BartPE/WinPE environment or something else I can run in that environment that could catch these? I can run HiJackThis in BartPE against the clients registry but it wont see this infection :/

    One other thing ive noted while watching the files through processmonitor as Autoruns and HiJackThis were being closed are new entries in the registry with jibberish names referencing files in non existant P: and Q: ending in .rkr
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Nexworks

    Without getting into revealing details, your deductions are correct in what tools are of use detecting this new type of malware infection.

    *I will point you in the direction of searching for threads here - keying on "AntiSpy Protector 2009 / Windows Antivirus Pro / Windows PolicePro " and the like - to see what's the underlining cause of "automatically closes all malware detecting/removal software". ;)

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds