05-01-2012 04:12 PM
I have this for a week or so. Tried with simple cleaning, but then realized that it doesn't work. I have read several long instructions, and all of them are different. I use Window 7, and Norton Security Suite. Norton keeps detecting Trojan.Gen.2 every 5 minutes. Also there are all other signs of the infection: computer cannot reboot, I have to go to a restore point, browser is redirected to unwanted sites, etc.
As far as I understand, every computer should be dealt individually.
Is anyone able to help?
Thanks,
Roman
Solved! Go to Solution.
05-01-2012 04:57 PM
What is the name of the file(s) and where were they located for detection.
Quads
05-01-2012 05:35 PM
Hi,
Thanks for replying!
The files are 00000002.@ and 80000064.@, 80000032.@ and located in c:\windows\assembly\temp\U
Roman
05-01-2012 05:47 PM
The Max++ (zeroaccess) group by the looks. Norton is deleting part of zeroaccess only, causing the rootkit not to work properly and BANG windows doesn't load properly either.
Are we talking about Windows 32 bit or 64 bit
Quads
05-01-2012 05:53 PM
Windows 7, 64
05-01-2012 06:08 PM
Please download hxxp://download.bleepingcomputer.com/farbar/FRST64.ex
Plug the flashdrive into the infected PC.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
05-01-2012 07:07 PM
It doesn't allow me to paste in into the body of the message (don't know how to disable a Spell checker).
Here is the file in the attachment
05-01-2012 07:21 PM
What are you playing with Virus removal for?? I can see the programs, documents and files you have downloaded or created, for instance virus removal.docx.
Quads
05-01-2012 07:29 PM
Well, I tried for a few days before asking for help. I had many suggestions on the Web - that resulted in downloading several programs. The file virus_removal.docx is my Word document I've created few days ago. I copied there few suggestions from the Web which included links to Malwarebytes, TDSKiller and something else. It didn't work.
I tried Malwarebytes and that Kaspersky's killer, but it couldn't reboot and started from the earlier point with all the stuff I had before.
I am posting now from another computer, on that computer I am still in System Recovery Option.
Thanks,
Roman
05-01-2012 07:41 PM
Download the fixlist.txt
Save it in the Flash Drive, next to FRST.exe
Run FRST as you did before, except that this time around, click on the Fix button and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
To others:-
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Quads
