Reply
Contributor
Violander
Posts: 16
Registered: ‎06-04-2012
Accepted Solution

Trojan.gen.2 - How to remove without relying on computer backup?

Hello, recently trojan.gen.2 has started popping up on my computer quite often - I followed teh instructions I found on Norton website - first running the inbuilt full system scan - then running the downloaded Eraser one. - nothing helped

I was wondering if there is something else I can try before using the third option (system restore)

Just some info

I have Windows 7 Home, 64-bit (PC)

I have Norton 360, updates etc

Aand this is my log

 

Full Path: c:\windows\installer\{64135f0b-49a7-7b9c-302c-e16326399828}\u\80000000.@
Threat: Trojan.Gen.2
____________________________
____________________________
On computers as of 04/06/2012 at 08:57:15
Last Used 04/06/2012 at 08:57:15
Startup Item No
Launched No
____________________________
____________________________
Unknown
Number of users in the Norton Community that have used this file: Unknown
____________________________
Unknown
This file release is currently not known.
____________________________
High
This file risk is high.
____________________________
Threat Details
Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________

____________________________
File Actions
File: c:\windows\installer\{64135f0b-49a7-7b9c-302c-e16326399828}\u\80000000.@
Blocked
____________________________
File Thumbprint - SHA:
d4ff45b8377f20fe24c46019d3366daa1bc644c3c1bf6da7d8f7e55e098504f1
____________________________
File Thumbprint - MD5:
a05ab6a7251b1f5073c9b1a6ce3e20e8
____________________________
 

 

Thanks for any help! 

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trojan.gen.2 - How to remove without relying on computer backup?

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

 

Download OTL   hxxp://oldtimer.geekstogo.com/OTL.exe   (change the hxxp to http) save it to your Desktop.

Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.

 

Disable Norton for say 30 minutes

 

Start OTL,  

Click the Scan All Users checkbox.

Change file age to 60 days

under  Copy and paste what is below between the lines


 


msconfig
activex
drivers32
netsvcs
C:\Program Files\Common Files\ComObjects\*.* /s
%systemroot%\*. /mp /s
%systemroot%\*. /rp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.sys
atapi.sys
explorer.exe
winlogon.exe

mswsock.dll
wininit.exe
services.exe

svchost.exe
tdx.sys
afd.sys
cdrom.sys
i8042prt.sys
netbt.sys
redbook.sys

mrxsmb.sys

/md5stop

HKEY_CURRENT_USER\Software\Classes\CLSID\{64135f0b-49a7-7b9c-302c-e16326399828} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64135f0b-49a7-7b9c-302c-e16326399828} /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs


 

Press the 

 

 

An OTL.txt will be created.

 

Quads

Contributor
Violander
Posts: 16
Registered: ‎06-04-2012

Re: Trojan.gen.2 - How to remove without relying on computer backup?

Hello, thanks for you help - i have done what you asked - here is the report (attached)

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trojan.gen.2 - How to remove without relying on computer backup?

[ Edited ]

While I create the first script to remove the first part.

 

a) do you have a flash drive??

 

If so I want you to copy the services.exe on to the Flash drive from this location  

 

C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

 

To make sure we have an extra backup copy.

 

Quads

Contributor
Violander
Posts: 16
Registered: ‎06-04-2012

Re: Trojan.gen.2 - How to remove without relying on computer backup?

Yes.

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trojan.gen.2 - How to remove without relying on computer backup?

I updated my last post above

 

Quads

Contributor
Violander
Posts: 16
Registered: ‎06-04-2012

Re: Trojan.gen.2 - How to remove without relying on computer backup?

Done.

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trojan.gen.2 - How to remove without relying on computer backup?

[ Edited ]

By the way if you are online and wonder if there is a reply to your thread, because the the forum does not auto refresh, you can just press F5 on the keyboard to reload the page.

 

Remove the Flash Drive from the PC.

 

Disable Norton for say 30 minutes

 

Start OTL,   under   Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom)  and run the script. (Red Run Fix Button)

 

The output log, should be placed in the C:\ _OTL folder after.

 

Quads

Contributor
Violander
Posts: 16
Registered: ‎06-04-2012

Re: Trojan.gen.2 - How to remove without relying on computer backup?

Hi, I did what you said and the output log is below.

 

Is this it then?

If so - thank you very much for your time and yoru help!!!  

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trojan.gen.2 - How to remove without relying on computer backup?

No there is a reason I said you you to place a copy of the good services.exe on your Flash Drive.

 

I have to now create another script for another program to log and move the next part as you have the Zeroaccess rootkit

 

You may now for the moment have Norton detecting other files in other locations, though annoying, that is OK.

 

Quads