Reply
Newbie
baixiwei
Posts: 1
Registered: ‎05-15-2012

Trojan.Gen.2 problem

[ Edited ]

Hi, I am having trouble getting rid of Trojan.Gen.2 and hope someone here can help. I saw some other posters had similar problems but, because my situation is a bit different from those I found, I am starting a new thread.

 

I am using Symantec Endpoint Protection version 11.0 on a Sony Vaio laptop running 64-bit Windows 7. Symantec lately pops up every few minutes telling me that the auto-protect scan found Trojan.Gen.2 in a file called 80000032.@ (always this name). It says the file was successfully quarantined, but then I get the same message again ... and again ...

 

Looking at "Details", Symantec says that the internet browser cache was deleted and the file 80000032.@, located in C:\Windows\Installer\...gobbledigook...\U, was quarantined successfully.

 

I think I started seeing this message several days ago, but it's only in the last day or so that it's started popping up every couple minutes. So far, I haven't noticed system performance to be affected in any other way (I can still turn the machine off and on normally, reboot normally, etc. and my web browsers - Firefox and IE - are not being rerouted).

 

Attached are some recent logs with details. Any help would be greatly appreciated.

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Trojan.Gen.2 problem

Please download hxxp://download.bleepingcomputer.com/farbar/FRST64.exe   (change the hxxp to http) and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.


On the System Recovery Options menu you will get the following options:

 

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt


  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

 

Quads

Symantec Employee
mithunsanghavi
Posts: 17
Registered: ‎10-12-2009

Re: Trojan.Gen.2 problem

Hello,

 

I would suggest you to check this Article:

 

Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec ...

 

and submit the Suspicious Files to the Symantec Security Response Team.

 

and Check these Threads:

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/80000032-Trojan-Gen-2/m-p/720302/high...

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-gen-2-80000000-removal-help/m-...

 

https://www-secure.symantec.com/connect/forums/how-stop-trojangen2-coming-my-computer

 

https://www-secure.symantec.com/connect/forums/how-stop-antivirus-repeatedly-detecting-same-threat

 

In the future, it would be best to post SEP product issues in the Connect forums, as this is a consumer product (Norton) forum.

 

https://www-secure.symantec.com/connect/security/forums/endpoint-protection-antivirus

 

Hope that helps!!

Thanks and Regards
--------------------------------------------------
Mithun Sanghavi, TSE, Symantec Corporation