TR/Rootkit.Gen Trojan Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Topspeed, May 21, 2010.

  1. Topspeed

    Topspeed Private E-2

    Your Windows XP Cleaning Procedure is very user-friendly and helpful. It seems tons of .dll files were removed by Combofix or Rootrepeal. My computer was infected by TR/Rootkit Trojan while I was doing research on the Internet last night.

    I would appreciate it very much if someone would look at the five logs attached and advise what volunerability exist on my computer that may have caused the attack and if all infected files have been removed. Thank you.

    ps. I prefer to have you to look over things and keep my computer up to date if it's okay, but are there resources where I can learn about how to comprehend or analyze these logs myself, too?
     

    Attached Files:

  2. Topspeed

    Topspeed Private E-2

    The 5th and last attachment is MGlog.zip. Thanks.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    IMHO - to be truly well-versed in understanding and using the various tools to detect malware/ analyzing the logs they produce/ proper and complete malware removal techniques involves formal training.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Topspeed

    The tools took care of the malware - just a couple of things to do:

    Referring to the READ & RUN ME FIRST. Malware Removal Guide
    • There are two anti-virus programs installed
      • AVG Free 9.0
      • Avira AntiVir Personal - Free Antivirus
    • No Java installed

    The desktop is the wrong place to have this: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe. Please delete it or move it elsewhere.

    If you choose to keep Avira AntiVir Personal, then use Add/Remove to uninstall AVG Free 9.0 > go here AVG Remover > download the AVG Remover(32bit) (avgremover.exe) > run it and re-boot > run it again.

    Now open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Then install the latest Sun Java Runtime Environment

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! [​IMG]
     
    Last edited: May 23, 2010
  5. Topspeed

    Topspeed Private E-2

    Dr. Moriarty, thanks for looking through the logs. I have a few lingering issues on my computer.

    :confusedAfter I set msconfig to Normal Startup, I'm getting two error messages when I boot up. They are:


    LogiTray.exe Unable to Locate Component dialog box.
    “This application has failed to start because MSVCR71.dll was not found. Reinstall the application may fix this problem.”

    LVCOMSX.exe Unable to Locate Component dialog box.
    “This application has failed to start because MSVCR71.dll was not found. Reinstall the application may fix this problem.”​

    What do these messages mean? Where do I find this MSVCR71.dll? How do I install it? Do you think the tools we ran removed it?

    After all the computer issues are resolved, should I reconfigure and keep my System Startup as Normal Startup or Selective Startup?​

    :confusedFive warnings reported by Avira antivirus. They are:

    Begin scan in 'C:\' <Local Disk>
    C:\MGtools.exe
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    [NOTE] This file is a Windows system file.
    [NOTE] This file cannot be opened for scanning.
    C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP881\A0133143.exe
    [0] Archive type: CAB SFX (self extracting)
    --> \Custom.ini
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP918\A0138491.exe
    [WARNING] The file could not be opened!

    What do I need to do to remove these five warnings?​

    :confused Three other questions about the steps you directed me to work on.

    I thought AVG 9.0 was an antispyware program. AVG and Avira AntiVir don’t seem to cause conflicts. In fact, both caught different malware this time. Can I keep both? I’m not certain, but AVG 9.0 seems to intercept malware earlier and more active. Which of the two anti-virus programs is better and which would you remove?

    I’ll have to research this “WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe” a bit. I can’t remember what it was downloaded to the desktop and used for. Do you know how important is it to save this file? If this is an essential boot up file, would saving this boot up file to an external backup RW-DVD make sense?

    At what step, should I delete Rootrepeal and setting.dat from my desktop?​
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    To answer your questions in order:

    1)
    2) MSVCR71.dll is present on your machine - it's shown working with C:\Program Files\Common Files\Microsoft Shared\Works Shared, Photoshop Album Starter Edition, and Microsoft.NET\Framework. I would suggest that you post in our Software Forum about repairing your Logitech software.

    3) Your machine should always be in Normal Startup Mode unless you are trying to diagnose problems -- msconfig should not to be used to permanently control startups.

    4) Recent bugs in many antivirus programs are detecting MGTools as malware... as explained in the Windows XP Cleaning Procedure
    The other warnings from Avira are not problems and many av's will give that same report/warning.

    AVG Free 9 is a combined antivirus and antimalware engine, LinkScanner, and also provides e-mail scanning. You should NOT have two anti-virus program installed on your machine. I personally use Avira along with other layered defenses suggested in the How to Protect yourself from malware! link.

    5) Info on "WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe" is found <click here>. A better location for this file save would be somewhere like "C:\Users\<your useraccount>\Downloads".

    6) Running the steps in our "Final Cleanup" will remove the tools and logs you no longer need.

    dr.m
     
    Last edited: May 24, 2010
  7. Topspeed

    Topspeed Private E-2

    Dr. Moriarty,

    Everything seems to be clean and working. Please let me know if I need to take action as I am still getting a "Page File" warning from AntiVir scan.

    I decided to install over my old Logitech Quickcam program and that seemed to have corrected the two missing MSVCR71.dll error messages at boot up.

    I installed a new personal firewall software (learning to use COMODO) and am working my way slowly through the steps in "How To Protect Yourself from Malware".

    Thanks very much for your help. I can't thank you enough in making the whole process as painless as possible.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds