Adlice forum

Software feedback => RogueKiller => Topic started by: Johyn on April 27, 2017, 07:05:16 PM

Title: Tough simplitec
Post by: Johyn on April 27, 2017, 07:05:16 PM
Greets!

Just about an unremovable PUP: Simplitec, in programdata. Roguekiller locate it, and supress it, but to get them (there are two of them) back in next scan. That doesn't seem really nasty, got it since a couple of week, but that's still anoyin, eh. :)
Title: Re: Tough simplitec
Post by: Curson on April 27, 2017, 07:11:21 PM
Hi Johyn,

Thanks for your feedback.
Could you please attach RogueKiller deletion report with your next reply ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 27, 2017, 07:33:35 PM
Sorry, how do I get that report?
Title: Re: Tough simplitec
Post by: Curson on April 27, 2017, 07:36:11 PM
Hi Johyn,

To export a report, go to the "History" tab, then to the "Scan Reports" section.
There, do a right click on the first line, the click on the "Export json" button.

Please then attach this JSON report with your next reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 27, 2017, 07:39:52 PM
Got only a 'supression' option...
Title: Re: Tough simplitec
Post by: Curson on April 27, 2017, 07:51:15 PM
Hi Johyn,

 Could you please check the content of the following directory ?
Quote
C:\ProgramData\RogueKiller\Logs

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 27, 2017, 08:04:53 PM
no logs, only changelogs...
Title: Re: Tough simplitec
Post by: Curson on April 27, 2017, 08:10:16 PM
Hi Johyn,

That's not normal.
Could you please redo a scan and check if the option to save a log is available at the end of it ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 28, 2017, 11:48:45 AM
Ok, here it is.
Title: Re: Tough simplitec
Post by: Curson on April 28, 2017, 07:25:45 PM
Hi Johyn,

The report is not complete, but the [Suspicious.Path] detection is legit.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 28, 2017, 08:31:07 PM
Ok, but what's lackin? I shouldn't mind the two 'simplitec'?
Title: Re: Tough simplitec
Post by: Curson on April 28, 2017, 08:38:58 PM
Hi Johyn,

Could you please do a screenshot of these detections ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 29, 2017, 04:14:05 PM
Is that ok?
Title: Re: Tough simplitec
Post by: Curson on April 29, 2017, 06:00:45 PM
Hi Johyn,

Yes, thats clearly PUP.
Please download Farbar Recovery Scan Tool (x64) (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to your Desktop.
Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 29, 2017, 06:58:58 PM
Ok,
Title: Re: Tough simplitec
Post by: Curson on April 29, 2017, 08:13:11 PM
Hi Johyn,

These folders are not visible in the reports. Anyway, there are some leftovers.
TeamViewer is installed as as service on your system. It's recommanded to uninstall it in case you don't use it.

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 29, 2017, 08:38:10 PM
Here,
Title: Re: Tough simplitec
Post by: Curson on April 30, 2017, 12:01:19 PM
Hi Johyn,

The PUP folder is not present anymore.
Could you please retry a scan with RogueKiller to check if the item is still detected ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 30, 2017, 03:19:28 PM
Yes, they disapear after Roguekilller supression, to be back in the morrow...
Made a new 'fix' scan:
Title: Re: Tough simplitec
Post by: Curson on April 30, 2017, 03:49:53 PM
Hi Johyn,

Something is reinfecting your computer.
Please follow the following tutorial : Malwarebytes Tutorial (http://www.adlice.com/documentation/malwarebytes/tutorial/).

Please attach the scan report with your next reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 30, 2017, 05:20:06 PM
Ok, new threats founds with malwarebytes (see log), but no simplitec, and it's still in roguekiller scan...
By the way, what's the diference between the two programs?
Title: Re: Tough simplitec
Post by: Curson on April 30, 2017, 06:07:41 PM
Hi Johyn,

MalwareBytes is edited by MalwareBytes Company and is a general scanner.
RogueKiller is specialized again advanced threads.

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on April 30, 2017, 07:18:19 PM
Ok, supressed simplitecs earlier, so they'll be back tomorow, with the fixlog... :)
Title: Re: Tough simplitec
Post by: Johyn on May 01, 2017, 02:29:12 PM
Ok,
Title: Re: Tough simplitec
Post by: Curson on May 01, 2017, 03:07:19 PM
Hi Johyn,

This is really troublesome.
Please download SystemLook (x64) (http://jpshortstuff.247fixes.com/SystemLook_x64.exe) and save it to your desktop.
Code: [Select]
:filefind
*simplitec*

:folderfind
*simplitec*

:regfind
*simplitec*
Note: The log can also be found on your Desktop entitled SystemLook.txt

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 01, 2017, 07:11:48 PM
Hop
Title: Re: Tough simplitec
Post by: Curson on May 03, 2017, 06:45:55 PM
Hi Johyn,

SystemLook did detect some folder that was not reported by FRST.
We are going to delete it with FRST.

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 04, 2017, 11:31:11 AM
Ok,
Title: Re: Tough simplitec
Post by: Curson on May 04, 2017, 12:53:06 PM
Hi Johyn,

It should be gone.
Is the simplitec folder still detected ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 04, 2017, 04:46:18 PM
Nope, still there...  :(
Title: Re: Tough simplitec
Post by: Curson on May 04, 2017, 04:58:41 PM
Hi Johyn,

We are going to check for rootkits.
Please attach the contents of TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically C:\)in your next reply.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 04, 2017, 07:41:41 PM
Ok, nothin found..
Title: Re: Tough simplitec
Post by: Curson on May 04, 2017, 08:00:03 PM
Hi Johyn,

Let's try another scanner.

 - Please download Kaspersky Virus Removal Tool (http://devbuilds.kaspersky-labs.com/devbuilds/KVRT/latest/full/KVRT.exe) and save it on your desktop..
 - Right click on KVRT.exe and select Run as Administrator.
 - Read the EULA, then select Accept.
 - Wait for Kaspersky Virus Removal Tool to initialize.
 - In the main screen, select Change parameters, place a checkmark in System drive, then click OK.
 - Click Start scan.
 - Wait for Kaspersky Virus Removal Tool to complete scanning.
 - When the scan is finished, select Neutralize all for all detected objects.
 - Close Kaspersky Virus Removal Tool when done.

Please then informe me if something is detected.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 05, 2017, 11:51:24 AM
Yes, one threat detected and eliminated, but simplitecs are still there...
Title: Re: Tough simplitec
Post by: Curson on May 05, 2017, 03:19:41 PM
Hi Johyn,

I'm sorry but I'm out of ideas.
I will ask my others security colleagues about this specific malware.
Thanks for your patience and understanding.

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 05, 2017, 04:02:03 PM
Thanks for YOUR patience and understandin, cheers!
Title: Re: Tough simplitec
Post by: Curson on May 11, 2017, 04:43:52 PM
Hi Johyn,

Sorry for the delay.
These folders may be created by a legitimate software.

Please download SystemLook (x64) (http://jpshortstuff.247fixes.com/SystemLook_x64.exe) and save it to your desktop.
Code: [Select]
:dir
C:\ProgramData\simplitec /s /md5
C:\Users\All Users\simplitec /s /md5
Note: The log can also be found on your Desktop entitled SystemLook.txt

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 13, 2017, 10:04:34 PM
Here, but nothin found i'm afraid...
Title: Re: Tough simplitec
Post by: Curson on May 14, 2017, 01:03:54 PM
Hi Johyn,

The simplitec folders are empty, that's why SystemLook didn't find anything.

The good new is this is nothing malicious, since they don't contain anything.
The bad new, however, is we still don't know why the are recreated at system startup.

Would you like to continue the investigation, knowning your computer is not at risk ?

Regards.
Title: Re: Tough simplitec
Post by: Johyn on May 14, 2017, 02:09:31 PM
As I told you, t'was mostly to get it clean, but I could live with it, sure. You surely have a beter use for time, and I should thank you for all that you've done already.
Many thanks! :)
Title: Re: Tough simplitec
Post by: Curson on May 14, 2017, 06:38:09 PM
Hi Johyn,

You are very welcome. :)
If I ever find the cause of these folders recreation, I will let you know for sure.

Regards.