WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
virus is still present...antivir just found it again today.

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
Does Antivir say where?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
tr/rootkit.gen2 - Page 1 DXwU4
tr/rootkit.gen2 - Page 1 VvYDg

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
C:\System Volume Information\_restore{93CB386A-A703-42F9-AFD5-3BF2CA4807EA}\RP32\A0032987.sys
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
C:\WINDOWS\temp\SMI294.tmp
[DETECTION] Is the TR/Rootkit.Gen2 Trojan

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
No problem, that's just restore points.

Congratulations!! Your PC is all clean! ;D

To uninstall ComboFix



  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


tr/rootkit.gen2 - Page 1 Combofix_uninstall_image

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)



  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.

=========



Please run OTL.exe.


  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Commands
    [emptytemp]
    [emptyflash]
    [clearallrestorepoints]
    [reboot]

    Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.
  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe


If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

======

Remove OTL:

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.


  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.


Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
=======

Download [URL="http://screen317.changelog.fr/SecurityCheck.exe"]Security Check[/URL] by screen317 and save it to your Desktop.

  • Double-click Security Check.exe to start the application
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Note: if a security program requests permission from dig.exe to access the Internet, allow it to do so.
=======

There are many things you can do to keep this from happening again. You can think of a computer like a car. It requires basic maintenance to keep in tip top shape and ready to go. Would you drive your car 100,000 miles without changing the oil? The same principle applies here.

For some helpful tips regarding why you were infected in the first place, what you can do to keep this from happening again, and routine basic maintenance you should be performing on your PC to keep it running, you may wish to review the following threads:

[URL="http://www.pchelpforum.com/fixed-hijackthis-logs/64964-so-you-want-prevent-happening.html"]So, you want to keep this from happening again?[/URL]
[URL="http://www.pchelpforum.com/fixed-hijackthis-logs/57400-how-did-i-get-infected.html"]How Did I Get Infected?[/URL]
[URL="http://www.pchelpforum.com/fixed-hijackthis-logs/59327-now-you-all-clean-afterwork.html"]tr/rootkit.gen2 - Page 1 Pchf_afterwork[/URL]

In your next reply:

Please confirm removal of the tools
Post the SecurityCheck log

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
tr/rootkit.gen2 - Page 1 DXwU4
tr/rootkit.gen2 - Page 1 VvYDg

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5535643 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 456 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Jeremy C
->Temp folder emptied: 64981870 bytes
->Temporary Internet Files folder emptied: 25688681 bytes
->Java cache emptied: 1178395 bytes
->FireFox cache emptied: 335583442 bytes
->Google Chrome cache emptied: 369198445 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 129108 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: My Computer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Opera cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 952 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 52201 bytes

User: Tami
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3353907 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 15255716 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 660 bytes

Total Files Cleaned = 783.00 mb


[EMPTYFLASH]

User: Admin
->Flash cache emptied: 0 bytes

User: Administrator

User: All Users

User: Default User

User: Jeremy C
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: My Computer

User: NetworkService
->Flash cache emptied: 0 bytes

User: Tami
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.31.0 log created on 01272012_182613

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
both OTL and Combofix were removed successfully.


Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Avira AntiVir Personal - Free Antivirus
ESET Online Scanner v3
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

Out of date Spybot installed!
Malwarebytes' Anti-Malware
Java(TM) 6 Update 25
Out of date Java installed!
Adobe Flash Player 11.1.102.55
Mozilla Firefox (x86 en-US..)
Mozilla Thunderbird (3.1.15) Thunderbird Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Avira Antivir avguard.exe
``````````End of Log````````````


thank you!!

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
Hello.
Quite a few old programs to update now.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Azureus
    Java(TM) 6 Update 25
    Spybot - Search & Destroy 1.5.2.20

Updating Java:

  • Download the latest version of Java SE Runtime Environment (JRE) 7 Update 1.
  • Click the "Download JRE" button to the right.
  • In the Window that opens, select your platform, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-7u1-windows-i586.exe that you downloaded to install the newest version.

Please download Firefox 9.0.1 and install it. It will install over version 9.0 you currently have installed, so you won't lose any bookmarked websites.

Download and install VLC Player 1.1.11
When installing, it will ask if you want to uninstall the old version first before it can install the new version, so please select yes and allow it to install.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
tr/rootkit.gen2 - Page 1 DXwU4
tr/rootkit.gen2 - Page 1 VvYDg

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
I dumped Azureus a long time ago, something lingers though. when I click on "remove" in "add or remove programs" I get this message:

"couldn't load main class"

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
Okay skip that for now and carry on with the rest.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
tr/rootkit.gen2 - Page 1 DXwU4
tr/rootkit.gen2 - Page 1 VvYDg

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
ok. all that is done, except the Azureus.

descriptiontr/rootkit.gen2 - Page 1 EmptyRe: tr/rootkit.gen2

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum