Looks like there are some serious rootkit components to this and our best bet would be to get combofix to run. Generally, when I see baddies such as this, I advise a reformat because of the nature of the rootkit beast.
If you'd like to continue, please do the following:
Please Download Win32kDiag and save it to your Desktop.
-- DoubleClick on Win32kDiag.exe to run it. Let it run for as long as it needs to.
-- When it says Finished – Press any key to exit, do that to exit the program.
-- You should now have a Win32kDiag.txt on your Desktop. Please post the entire log for me and we’ll go from there.
UPDATE: We were able to change the name of the Malware file and it ran for about an hour, 85,000+ files then crapped out.
We have removed the two hard drives from the computer and have tried installing them in another computer to see if we can "rescue" the data files. . . but it seems like the f**king virus might have done some hardware damage as well.
Any thoughts? At this point we just need to recover lots of data files before we re-format
At this point we just need to recover lots of data files before we re-format
At this point, without seeing exactly what is infecting you, It is difficult to comment with any accuracy - It sounds like you might have more than one infection.
Also, due to the rootkits involved with the infection you noted, putting those hard drives in another computer for data recovery is a bad idea - you could end up with another compromised machine.
-- Can you get me a HijackThis log?
-- Try running MBA-M in Safe Mode and see if it completes
-- If not, run it until it has found a bunch of baddies - abort the scan manually and then see if you are able to have it clean what it has found and run it again.
-- When MBA-M craps out, what file is it "hanging" on?
Finally: a breakthru: My computer guy was able to "partition" off parts of the hard drive and isolate the OS. (Can you tell i have NO idea what Im talking about?) He then was able to re-load the OS and we seem to have solved the problem.
To all of you: THANKS! There MUST be a way to stop or prosecute these individuals that perpetrate this kind of destruction.