06-04-2012 01:04 AM
Hello, recently trojan.gen.2 has started popping up on my computer quite often - I followed teh instructions I found on Norton website - first running the inbuilt full system scan - then running the downloaded Eraser one. - nothing helped
I was wondering if there is something else I can try before using the third option (system restore)
Just some info
I have Windows 7 Home, 64-bit (PC)
I have Norton 360, updates etc
Aand this is my log
Full Path: c:\windows\installer\{64135f0b-49a7-7b9c-302c-e163
Threat: Trojan.Gen.2
____________________________
____________________________
On computers as of 04/06/2012 at 08:57:15
Last Used 04/06/2012 at 08:57:15
Startup Item No
Launched No
____________________________
____________________________
Unknown
Number of users in the Norton Community that have used this file: Unknown
____________________________
Unknown
This file release is currently not known.
____________________________
High
This file risk is high.
____________________________
Threat Details
Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________
____________________________
File Actions
File: c:\windows\installer\{64135f0b-49a7-7b9c-302c-e163
Blocked
____________________________
File Thumbprint - SHA:
d4ff45b8377f20fe24c46019d3366daa1bc644c3c1bf6da7d8
____________________________
File Thumbprint - MD5:
a05ab6a7251b1f5073c9b1a6ce3e20e8
____________________________
Thanks for any help!
Solved! Go to Solution.
06-04-2012 04:04 PM
Please do not run any tools unless instructed to do so.
Please read every post completely before doing anything.
)
Download OTL hxxp://oldtimer.geekstogo.com/OTL.exe (change the hxxp to http) save it to your Desktop.
Double click on OTL.exe to run it. Right click OTL.exe and select run as administator for Vista and Win 7.
Disable Norton for say 30 minutes
Start OTL,
Click the Scan All Users checkbox.
Change file age to 60 days
under
Copy and paste what is below between the lines
msconfig
activex
drivers32
netsvcs
C:\Program Files\Common Files\ComObjects\*.* /s
%systemroot%\*. /mp /s
%systemroot%\*. /rp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.sys
atapi.sys
explorer.exe
winlogon.exe
mswsock.dll
wininit.exe
services.exe
svchost.exe
tdx.sys
afd.sys
cdrom.sys
i8042prt.sys
netbt.sys
redbook.sys
mrxsmb.sys
/md5stop
HKEY_CURRENT_USER\Software\Classes\CLSID\{64135f0b-49a7-7b9c-302c-e16326399828} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64135f0b-49a7-7b9c-302c-e16326399828} /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
Press the 
An OTL.txt will be created.
Quads
06-05-2012 02:07 AM
Hello, thanks for you help - i have done what you asked - here is the report (attached)
06-05-2012 02:23 AM - edited 06-05-2012 02:52 AM
While I create the first script to remove the first part.
a) do you have a flash drive??
If so I want you to copy the services.exe on to the Flash drive from this location
C:\Windows\winsxs\amd64_microsoft-windows-s..s-ser
To make sure we have an extra backup copy.
Quads
06-05-2012 02:51 AM
Yes.
06-05-2012 02:53 AM
I updated my last post above
Quads
06-05-2012 03:45 AM
Done.
06-05-2012 11:40 AM - edited 06-05-2012 11:42 AM
By the way if you are online and wonder if there is a reply to your thread, because the the forum does not auto refresh, you can just press F5 on the keyboard to reload the page.
Remove the Flash Drive from the PC.
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
06-05-2012 03:35 PM
Hi, I did what you said and the output log is below.
Is this it then?
If so - thank you very much for your time and yoru help!!!
06-05-2012 03:47 PM
No there is a reason I said you you to place a copy of the good services.exe on your Flash Drive.
I have to now create another script for another program to log and move the next part as you have the Zeroaccess rootkit
You may now for the moment have Norton detecting other files in other locations, though annoying, that is OK.
Quads
