![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello all,
I am new here but ran across this forum while looking for a solution for the problem I have recently encountered. This seemed like the most legit place of several I have looked at so I'm hoping to get some help. Any help any one can give is appreciated. To give a brief problem description...I recently encountered a screen pop up that said something about illegal activity being performed on my computer (which is not the case) and that the computer had been locked and all I had to do was send money via some website and it would be unlocked. I restarted and got the same thing. I was able to restart in safe mode and avoid the screen. Additionally, I am having problems with google redirects. I ran malwarebytes and there was something called rootkit.0access.h found. After doing some reading I have figured out that this is way above very limited knowledge. I have run the full spectrum of programs following the directions in the sticky note for malware and have attached copies of the logs. Just to note, however, I was unable to get the combofix or the rootrepeal to work. Combofix just kept freezing and rootrepeal continued to give me an error. Thanks again for any help you can provide. Jeff |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Ok. I have just run TDSSkiller and MBRcheck. I have attached both logs for you. I anxiously await you next instructions. Thank you for your help.
|
|
#4
|
||||
|
||||
|
1. Java(TM) 6 Update 20 <--- uninstall outdated Java.
2. C:\Windows\System32\dds_trash_log.cmd <--- Delete this file. 3. Download Cleano 0.61 Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image) Attachment 148092 Click clean now and exit the program. 4
5. Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply. 6.Please download this and transer it to your PC. Please download Farbar Service Scanner and run it on the computer with the issue.
7. Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Ok. Done with all of that. I tried running the combofix like you said but still did not work. Everything else ran no problem and I have attached the logs. Thank you again for your help and I'll wait for your next set of instructions.
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You need to run Farbar's Service Scanner as requested and attach the log from it. A log from FSRT was not requested ( at least not yet ) and you did not run it properly anyway.
It has to be run after booting in the System Recovery Environement. You simply tried running it directly from Windows.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
Ok, sorry about that. I think the link for the farber service scanner actually took me to download FRST. Anyway, I got FSS and have run it and included the log. Thanks.
|
|
#8
|
||||
|
||||
|
Quote:
From this log and your MGtools logs, we can see your BFE and Windows Firewall services are not running. Also so registry entries have been deleted and some system files may have been modified. Please shutdown your protection software from Microsoft and then follow the below instructions. Now run the C:\MGtools\FixWFW.bat file by right clicking on it selecting Run As Administrator. Now download SubInACL.msi from Microsoft.
Now shutdown your protection software again to avoid having it get in the way of our fixes. Now run the C:\MGtools\FixWFW.bat file again ( yes we are repeating this ) by right clicking on it selecting Run As Administrator Please click Start and in the Start Search box type type services.msc into the box. When you see the services.msc icon appear up above in the list, right click on it and select Run As Administrator. This will open up the Services form. Scroll down to the Base Filtering Engine Service service and double click on it. Set the Startup type to Automatic and then close the form for the BFE service. Now locate the Windows Firewall Service service and Start it and set the Startup type to Automatic, Did this Start? Now close the above services forms. please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
Java(TM) 6 Update 20 Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) After clicking Fix, exit HJT. Now install the current version of Sun Java from: Sun Java Runtime Environment Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day). C:\WINDOWS\Temp C:\Users\jeffrey.walters\AppData\Local\Temp\ Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
Kestrel13! (04-16-12) | ||
|
#9
|
|||
|
|||
|
Ok, I have gotten about half way through but I am trying to run the files from services.msc and I don't see either one of them in the list. I am right clicking and running services.msc as administrator from the start menu but still not seeing the files you mention in the list.
I didn't go any further than that. Please let me know if there is something I might be doing wrong or if there is another place to find these files. Thanks. |
|
#10
|
|||
|
|||
|
Ok, check that, I tried again and did see the files and set both of them to automatic. When i clicked start on the windows firewall service I got an error
"Error 1068: the dependency service or group failed to start" So I still have not gone any further in your last set of instructions. I'll wait for your reply to see what I need to do next. Thanks, again. |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Just continue on with the rest of those instructions and attach the requested logs.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
Ok I finished with everything.
As stated before the windows firewall did not start but gave me the Error 1068. I also did not find the following file when I ran analyze.exe O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) but I did find and remove the other 2 files you mentioned. Everything else is done and there were no problems. The machine seems to be running well now. I am not getting any more warnings from malwarebytes about rootkit.0access.h being quarantined. I will wait on your next set of instructions or for the all clear if you think everything is good to go. |
|
#13
|
||||
|
||||
|
I suggest that you get Windows 7 updated to SP1.
You need this update and that may even be why some if not all those files are being shown as incorrect. I suggest that you go to Windows Update and get your Windows 7 SP1 update installed now. See >> http://windows.microsoft.com/en-US/windows7/install-windows-7-service-pack-1 After updating rerun Farbar's Service Scanner and attach a new log. Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| help removing RootKit.0access.h | fluidmedia | Malware Removal | 19 | 03-13-12 22:25 |
| I can't remove RootKit.0access.h | oldreb | Malware Removal | 17 | 03-11-12 03:20 |
| RootKit.0access.h - help! | sscab | Malware Removal | 34 | 03-09-12 02:19 |
| RootKit.0Access.H | ElGato | Malware Removal | 18 | 02-27-12 16:55 |
| rootkit.0access and other malware | deeps | Malware Removal | 46 | 10-27-11 23:23 |