Seeking Help for removal of 0Access rootkit and other possibles

Discussion in 'Malware Help (A Specialist Will Reply)' started by UecITtech, Oct 9, 2012.

  1. UecITtech

    UecITtech Private E-2

    Hello first time poster here, so please let me know if I am not following proper protocol to post and seek assistance. I have read the Read and Run me first article and have attached related files per the document.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ask Toolbar <--- Uninstall this junk.

    Re run Hitman, TDSSKiller and RogueKiller (no fixes, just scans) and attach their logs.

    Delete these files:

    C:\Users\Trevor.Trevor-PC2011\AppData\Roaming\uplcs.dll
    C:\Users\Trevor.Trevor-PC2011\AppData\Roaming\utple.dll

    Delete this folder unless you know what it is for.

    C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. UecITtech

    UecITtech Private E-2

    Thank you very much for your assistance with this matter.
    It intially appeared there were about 6 malware items on this machine. (Our Staff Engineers PC) I Reran Hitman,Rogue Killer and TDSS Killer with just scans. Attached is MGtools log file. System appears stable, able to access various directories and files without major issues so far. I noticed I had forgot to attach the malware bytes log do you need it or goes it get sent with the MG tools log information?
     

    Attached Files:

  4. UecITtech

    UecITtech Private E-2

    Deleted the dll's and questionable directory mentioned .
    Uninstalled Ask toolbar . My guess is that got put there via an adobe update.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    attach their logs then please. You can also add the log from malware bytes.
     
  6. UecITtech

    UecITtech Private E-2

    Here you go. Again thanks for the help!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete the ASK item.

    What issues remain now? Logs look good.
     
  8. UecITtech

    UecITtech Private E-2

    ReRan Hitman and deleled the ASK item.
    Upon Reboot was confronted with a BSOD 0x0000008E stop error
    rebooted and reran Rogue Killer and deleted the items it found
    reran roguekiller (just scan) it found nothing.
    Could not do windows updates so ran Windows Repair by tweaking.com
    had it repair following
    Reset Registry Permissions
    Repair windows firewall
    Repair Windows Updates
    After reboot updates now worked ... ran windows updates rebooted all seems good. reran defogger and renabled .
    Ran Dell Diagnostics on PC for memory as 8E BSOD can be result of bad ram also Memory check seemed fine... but may order some more ram as this machine could use more anyway.
    Everything seems to running good now last scans on Symantec Endpoint,Malwarebytes, and Super Antivirus did not find anything
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent, good to hear. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds