Jump to content

Rootkit.0Access (System Check)


qaze34

Recommended Posts

Merged 3 post

Hey malwarebytes, hopefully you guys can help me :D

First i will tell you what I know and what is happening.

Yesterday while using the computer All a sudden a thing called "system check" had popped up, I knew immediately that it was malware

so thusly i ran a scan with malware bytes. It said that it cleaned it, however after the restart the problem was clearly not fixed. I shut off again

and rebooted in Safe mode with networking, I downloaded combofix, that said that it worked too. After restart I was expecting it to work.

However I as the computer turns back on, i notice that it is working. (i used Unhide.exe) Everything was working satisfactory and I seemed to have no problems. However now I cannot access the internet. Not with chrome, mozilla, or ie. I have tried to reset the winsock. Get rid of any proxy settings, but still doesnt work. Also although seemingly working again, when I run malwarebytes it still tells me I have this malware. I will post the things below.

MalwareBytes log:

Malwarebytes Anti-Malware (Trial) 1.60.1.1000

www.malwarebytes.org

Database version: v2012.02.19.05

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

killoran :: HOME [administrator]

Protection: Disabled

2/20/2012 12:03:05 PM

mbam-log-2012-02-20 (12-03-05).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 215714

Time elapsed: 3 minute(s), 7 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 3

C:\WINDOWS\system32\MSMQTriggers.dll (RootKit.0Access.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\trufos.dll (RootKit.0Access.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wudfsvc.dll (RootKit.0Access.H) -> Quarantined and deleted successfully.

(end)

__________________________________________________________________________________________________________

Here is a log called "DDS" that i read you are sposed to post on here

https://www.virustotal.com/file/07c83deba19e1149f78713381dc837c221f645374f6c745f6fa254f67064bcd6/analysis/1329764330/

dds.txt

And here is the one called "attach"

https://www.virustotal.com/file/75d4684ccd6150cdbb9699e7fb43bed529d4c3b336071f12ee71e41defa2ad3f/analysis/1329764648/

attach.txt

_______________________________________________________________________________________________________________

alright those are the only logs I have right now, any help that someone would be able to give me would be absolutely awesome, thank you so

-Qaze34

Come on I really need help :/

Bump

bump

Link to post
Share on other sites

Hello and :welcome:

You have a nasty rootkit on your computer. Please read the following information first.

BACKDOOR WARNING

------------------------------

One or more of the identified infections is known to use a backdoor.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.

COMBOFIX

---------------

Please download ComboFix from one of these locations:


Bleepingcomputer
ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Query_RC.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

Link to post
Share on other sites

  • 1 month later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.