Virus removed but lingering problem

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I've removed various virus and trojan programs I had on my machine and now I
have 3 lingering problems.

1. When I start up I get and error message refering to rrot.exe having a
problem loading. the message reads "Debug Assertion Failed" (a C++ error
message) I can't find anything relating to this file on the net but when I
disable it (through msconfig) I can't get connected.

2. When I load Zone Alarm I can't get on the net.

3. Windows firewall is not avaialble to turn on. The choices on that screen
are all grayed out and are not selectable.

Anyone have any suggestions?
 
Yes! Change your posted name. This is NOT a teen chat room.

--
Regards,

Richard Urban
Microsoft MVP Windows Shell/User

Quote from: George Ankner
"If you knew as much as you think you know,
You would realize that you don't know what you thought you knew!"
 
Hey Richard,

why not OPEN yer eyes and read, his name is "pkerr" not pecker. How do u
know this guy's name is not Paul Kerr?



If your not helping provide a solution keep your comments to yourself.



/////



What is associated with the file rrot.exe? Can you give the full path of the
file location?

Did you check Zone alarm to make sure it is allowing outbound traffic on
your NIC?

Are you running PRO or home edition?



Vincent Lape
 
From: "pkerr" <[email protected]>

| I've removed various virus and trojan programs I had on my machine and now I
| have 3 lingering problems.
|
| 1. When I start up I get and error message refering to rrot.exe having a
| problem loading. the message reads "Debug Assertion Failed" (a C++ error
| message) I can't find anything relating to this file on the net but when I
| disable it (through msconfig) I can't get connected.
|
| 2. When I load Zone Alarm I can't get on the net.
|
| 3. Windows firewall is not avaialble to turn on. The choices on that screen
| are all grayed out and are not selectable.
|
| Anyone have any suggestions?

There are anti virus News Groups specifically for this type of discussion.

microsoft.public.security.virus
alt.comp.virus
alt.comp.anti-virus

If disabling "rrot.exe" blocks acces to the Internet then it may use a Layered Service
Provider (LSP) plug-in to the Windows WINSOCK.

Download Winsock XP Fix -- http://www.snapfiles.com/get/winsockxpfix.html
Use this to remove malware LSP entries and then disable rrot.exe and reboot the PC.

Check to see if you have Internet access. If you do, please perform the following...

For non-viral Malware...

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

BHODemon
http://www.definitivesolutions.com/bhodemon.htm

For viral Malware...

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *
 
Vince,
Thanks!! It's Patrick.

As to the rrot.exe file it is in Windows\system32

XP Pro

I have Zone alarm unloaded right now so that's kind of a secondary issue but
I'll check to see what it is allowing. I was using the default values though.

My big concern is that i can't get to MS firewall. It is grayed out.. with
it off and no way to turn it on.

Someone suggested doing sfc /scannow but it is still unavalable.
 
Thanks for the suggestions... I'll start working on those things.

David H. Lipman said:
From: "pkerr" <[email protected]>

| I've removed various virus and trojan programs I had on my machine and now I
| have 3 lingering problems.
|
| 1. When I start up I get and error message refering to rrot.exe having a
| problem loading. the message reads "Debug Assertion Failed" (a C++ error
| message) I can't find anything relating to this file on the net but when I
| disable it (through msconfig) I can't get connected.
|
| 2. When I load Zone Alarm I can't get on the net.
|
| 3. Windows firewall is not avaialble to turn on. The choices on that screen
| are all grayed out and are not selectable.
|
| Anyone have any suggestions?

There are anti virus News Groups specifically for this type of discussion.

microsoft.public.security.virus
alt.comp.virus
alt.comp.anti-virus

If disabling "rrot.exe" blocks acces to the Internet then it may use a Layered Service
Provider (LSP) plug-in to the Windows WINSOCK.

Download Winsock XP Fix -- http://www.snapfiles.com/get/winsockxpfix.html
Use this to remove malware LSP entries and then disable rrot.exe and reboot the PC.

Check to see if you have Internet access. If you do, please perform the following...

For non-viral Malware...

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

BHODemon
http://www.definitivesolutions.com/bhodemon.htm

For viral Malware...

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *
 
From: "pkerr" <[email protected]>

| Thanks for the suggestions... I'll start working on those things.
|
| "David H. Lipman" wrote:
|

An alternate way to fix WINSOCK can be done *IF* you have WinXP SP2 installed.

Open a Command Prompt and enter the following command line...
netsh winsock reset catalog

Or from; Start --> Run
%comspec% /c netsh winsock reset catalog
 
I feel sorry for you with those initials. Perhaps P. Kerr would look better
than pkerr (pecker).

--
Regards,

Richard Urban
Microsoft MVP Windows Shell/User

Quote from: George Ankner
"If you knew as much as you think you know,
You would realize that you don't know what you thought you knew!"
 
I feel sorry for you that you would think that. It's actually the first time
it's EVER come up.
 
Back
Top