Trojan.gen.2

Discussion in 'Malware Help (A Specialist Will Reply)' started by JamieMac, Feb 8, 2011.

  1. JamieMac

    JamieMac Private E-2

    Hi all, I have moved across from my previously favourite geek site (geekstogo.com) as they don't seem to be able to help, so here's a challenge :-D.

    5 year old Dell Inspiron running Win 7 home premium 3 Gb RAM. Problem is Symantec Endpoint Protection keeps popping up with messages about quarantining endless tmp files which are apprently infected with trojan.gen.2. I am not experiencing any other side effects but this looks like a potentially devious bug so I'd like to get rid of it.

    So on Sunday I spent much of the day running the settings and tools required to generate logs for attaching to this message (as instructed in READ ME FIRST with endpoint protection definetly turned off) , BUT combofix keeps killing me. I.e. after running combofix I have no internet connection and any attempt to run any functions like internet explorer, cmd, network and sharing centre, registry editor all give some message about "Illegal operation attempted on a registry key that has been marked for deletion".

    So I then have to do a restore (using my Win 7 install DVD as no Win 7 restore functions work) and thus loose all the log files I have generated up to that point?

    Any help gratefully received?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A reboot will correct everything. ;) Then you can attach the logs from running our procedures.
     
  3. JamieMac

    JamieMac Private E-2

    Thanks Kestrel, slightly frustrated that it doesn't say that in the ComboFix instructons ? As it takes so long to run all the necessary logs I won't be able to do it until the weekend so I'll keep this post open if that's OK?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh my, I did not realise you had formatted due to the error. I just read what you said properly. It was not a common problem, but I am seeing it alot lately. How I first came across it was when fixing a friends laptop. It was quite worrying until I rebooted and everything righted itself again. Perhaps we could put this into the instructions somewhere.

    Yes, will keep this thread open. :)
     
  5. JamieMac

    JamieMac Private E-2

    Ok Kestrel,

    I have got a bit further, rebooting after ComboFix resolved all those reg key messages. I am now stuck with RootRepeal 1.3.5.0 giving this error message:

    10:14:52: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000ec)
    10:14:52: DeviceIoControl Error! Error Code = 0x1e7
    10:14:52: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000ec)

    I have closed all anti virus services and firewall.

    I have attached the follwing logs to this message to show I have completed:
    • SuperAntiSpyWare
    • MalWareBytes (quick and full scans)
    • ComboFix

    I have yet to do RootRepeal and MGTools as I am stuck at this RootRepeal..
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Skip Rootrepeal and continue on.
     
  7. JamieMac

    JamieMac Private E-2

    OK I have run MGTools and attached zip log files..
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any problems. Is your antivirus still detecting threats?

    Running from: c:\users\Camilla\Downloads\MajorGeeks - Antivirus tools\ComboFix.exe <--- The instructions said to run Combofix directly from the desktop so please move it there now.

    C:\Users\Camilla\Downloads\MajorGeeks - Antivirus tools\MGtools.exe <--- Delete this. Not the location you should have downloaded it to.

    • Ask Toolbar <--- Uninstall this garbage.
    • Java(TM) 6 Update 5 <--- Outdated, uninstall.
    • McAfee Security Scan Plus <--- Uninstall this too.

    Download Ccleaner (which was part of the procedures), and run it. Just the cleaner side of things, do not run registry scans.

    Tell me what malware problems remain.
     
  9. JamieMac

    JamieMac Private E-2

    Ok Thanks,

    Do you need me to rerun both Combo Fix and MG from the desktop?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome.
    No. I said to delete MGTools.exe and to MOVE Combofix.exe to the desktop. Did not ask you to re run either.

    Are there any more problems or is everything running as it should? :)
     
  11. JamieMac

    JamieMac Private E-2

    Ok I have deleted MGTools.exe and moved ComboFix.exe to my dektop. Also deinstalled Ask Toolbar, Java(TM) 6 Update 5 and McAfee Security Scan Plus.

    I did not run Ccleaner beacuse I don't see it mentioned anywhere in the notes on http://http://forums.majorgeeks.com/showthread.php?t=139681 ?

    I have now reactivated symantec endpoint protection and it looks clear so far, I guess that means no more Trogan.Gen.2 although I'm not sure how to be certain?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As long as Endpoint is not detecting anything, then all looks good and you can now follow final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. JamieMac

    JamieMac Private E-2

    Ok thanks Kestrel, I'll do this as soon as I get back home mid week.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok! Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds