Need help fully removing rootkit.0access

Discussion in 'Malware Help (A Specialist Will Reply)' started by GEG7122, Sep 6, 2012.

  1. GEG7122

    GEG7122 Private E-2

    I have a system that was running McAfee which is what indicated the initial issue, ran scan and deleted what it found, then ran MalwareBytes and deleted what it found. Still after that I still had indications from Mcafee that the rootkit still existed. The system is running Win7 Home Premium. I've run all the diags suggested from this site and have the logs available. Thanks ahead for any help.
     
  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, GEG7122 :)

    Please attach those logs here. (How to attach)
     
  3. GEG7122

    GEG7122 Private E-2

    Here are the 5 logs.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Ask Toolbar
    • Java(TM) 6 Update 32

    __

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Program Files (x86)\Ask.com /d
    type "C:\Users\Mary Jane\Desktop\RKreport[2].txt" /c
    C:\Users\Mary Jane\AppData\Local\Temp\dump.dat
    [COLOR="DarkRed"]:reg[/COLOR]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{165B00E3-B74A-4D15-8766-E623C9A96DA9}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [COLOR="DarkRed"]:commands[/COLOR]
    [resethosts]
    [clearallrestorepoints]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    Let me know how things are working after you have completed the above.
     
  5. GEG7122

    GEG7122 Private E-2

    I have attached the OTL log file and have opened and closed programs and have gone to other web site without issues so far.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    That's good ;)

    One more thing that should be performed:

    http://img805.imageshack.us/img805/9659/rktigzy.gif Delete items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Once the scan is complete, press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[4].txt
    Attach RKreport[4].txt to your next message. (How to attach)
     
  7. GEG7122

    GEG7122 Private E-2

    Here's the rogue killer log.
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  9. GEG7122

    GEG7122 Private E-2

    Thanks again for all the help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds