Reply
Contributor
tleahy
Posts: 20
Registered: ‎07-02-2009

Re: Can't get rid of Trojan Horse

Hello,

 

   Malwarebytes seemed to install okay and there was an icon on the desktop but it never started after the install and if you click on the desktop icon nothing happens.

 

     Regards,

     tleahy

Contributor
tleahy
Posts: 20
Registered: ‎07-02-2009

Re: Can't get rid of Trojan Horse

Hello,

 

   Went and found the Malwarebytes executable and renamed it to seventh and then it seems to be running now. Will get back to you.

 

           Regards,

           tleahy

dbrisendine
Posts: 5,562
Kudos: 1,282
Solutions: 263
Registered: ‎10-06-2008

Re: Can't get rid of Trojan Horse

[ Edited ]

Good move on the rename.  Let us know.

 

Note: After running MBAM scan and posting log here, install v3 and update the definitions by manually running LiveUpdate until it says there are no more.  Turn on the Early Load option by going into the settings under Antivirus or Administrative Settings.  After that disconnect from the Internet and then reboot your machine (if you do not disconnect the RootKit will call for reinforcements).  When the boot is finished, follow all the messages that may pop up as N360 removes the malware.  Then connect to the Internet and post back here.

Message Edited by dbrisendine on 07-04-2009 11:28 PM
Contributor
tleahy
Posts: 20
Registered: ‎07-02-2009

Re: Can't get rid of Trojan Horse

Hello,

 

  MBAM ran and produced a log file (attached) I let it get rid of the files that it wanted to but at the end it had the message.

 

Certain Items could not be removed but will be deleted on reboot

 

C:\\Program Files\Internet Exporer\msimg32.dll

 

    Your computer needs to be restarted to complete the removal process. Would you like to continue:

 

                     Yes  No

 

  which should I click Yes or No? and what should I do afterwards.

 

dbrisendine
Posts: 5,562
Kudos: 1,282
Solutions: 263
Registered: ‎10-06-2008

Re: Can't get rid of Trojan Horse


tleahy wrote:

Hello,

 

  MBAM ran and produced a log file (attached) I let it get rid of the files that it wanted to but at the end it had the message.

 

Certain Items could not be removed but will be deleted on reboot

 

C:\\Program Files\Internet Exporer\msimg32.dll

 

    Your computer needs to be restarted to complete the removal process. Would you like to continue:

 

                     Yes  No

 

  which should I click Yes or No? and what should I do afterwards.

 


 

Click NO.  Install v3 and update it by running a manual LiveUpdate untill there are no more updates.  Turn on Early Load by going into the Settings (either in Administrative Tools or AntiVirus); then click Apply, OK, OK and then diconnect from the Internet.  Then reboot and let N360 find and delete the RootKit; follow the messages N360 may pop up.  When this is done, connect to the Internet and post back here.
Contributor
tleahy
Posts: 20
Registered: ‎07-02-2009

Re: Can't get rid of Trojan Horse

Hello,

 

  Ran into a bit of a problem. When I tried to install Norton 360 v 3.0 the system locked up. I rebooted leaving the PC disconnected from the internet and after a few tries got Norton 360 3.0 to install. When it needed to connect to the internet to Activate I let it. Also after one download of updates it wanted to reboot.

 

   Anyway eventually I got Norton 360 3.0 installed and it seems to have taken care of everything. Attached are RootRepeal, GMER and Hijack this scans it looks like everything is okay now.

dbrisendine
Posts: 5,562
Kudos: 1,282
Solutions: 263
Registered: ‎10-06-2008

Re: Can't get rid of Trojan Horse

Does anything show up on a N360 full system scan? 

 

If not, then we're happy this long process worked out for you.  Sorry it took so long but this will keep you cleaner that previous versions.  Post back if you have any more questions or need help.  Thank you for your patience in this matter.

Contributor
tleahy
Posts: 20
Registered: ‎07-02-2009

Re: Can't get rid of Trojan Horse

Hello,

 

   Nothing shows up on the Norton 360 Scan. Thank you for your patience and assitance.

 

          Best Regards,

          tleahy