Please help me remove Rootki.0Access

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by czarqwerty, Jul 24, 2012.

  1. czarqwerty

    czarqwerty Private E-2

    Please help me remove Rootkit.0Access

    My wife was browsing the web this morning when Security Essentials 2012 appeared. I used Malwarebytes Anti-Malware to remove it, but it cannot remove Rootkit.0Access.
    I followed the guide and the log files are attached.
    Microsoft Security Essentials will not run and neither with Windows Update.

    Of note in the RogueKiller log, I was using teamviewer at the time to connect to her computer so I could try and diagnose it.

    Thank you for your help!!
     

    Attached Files:

    Last edited: Jul 24, 2012
  2. czarqwerty

    czarqwerty Private E-2

    Thank you for looking. I was able to get it removed after several reboots. All of the tools are reporting the computer as clean. I'll keep an eye on it.
     
  3. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, czarqwerty

    I understand that you have probably removed the rootkit on your own. Just to be sure, make sure these two folders are completely removed:
    • c:\windows\installer\{be212968-f2b4-f6de-d91d-2996d59978cd}
    • c:\users\beyer\appdata\local\{be212968-f2b4-f6de-d91d-2996d59978cd}
    And make sure that c:\windows\system32\services.exe is now legit because it was infected.

    Let me know if you need additional assistance.

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  4. czarqwerty

    czarqwerty Private E-2

    Thank you for taking the time to look at the files. Yes, I have confirmed that those folders have been removed from my computer.
     
  5. thisisu

    thisisu Malware Consultant

    No problem. Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds