Reply
Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: here is the attachment

That is not showing it

 

Please read carefully and Slowly

 

 Please scan with ESET next 


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

here is the eset log file.

i hope I did this right.   thanks for your help.

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Trojan rootkit A.........

Where is Norton Detecting the Trojan.Rootkit.Alureon  (though I can't find it in the database)

 

Quads

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

Re: Trojan rootkit A.........

when I ran 360 scan this morning it didn't show up.

I have no idea why,    Thanks for all your help.

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

Re: Trojan rootkit A.........

I found it when I did another eset scan.

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

Re: Trojan rootkit A.........

I think I made a mistake, i forgot to uncheck the delete button when I ran that last scan.   I hope this doesn't mess things up. 

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Trojan rootkit A.........

Download OTL   hxxp://oldtimer.geekstogo.com/OTL.exe   (change the hxxp to http) save it to your Desktop.

Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.

 

Disable Norton for say 30 minutes

 

Start OTL,  

Click the Scan All Users checkbox.

Change file age to 60 days

under  Copy and paste what is below between the lines


 


msconfig
activex
drivers32
netsvcs
C:\Program Files\Common Files\ComObjects\*.* /s
%systemroot%\*. /mp /s
%systemroot%\*. /rp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.sys
atapi.sys
explorer.exe
winlogon.exe

mswsock.dll
wininit.exe
services.exe

svchost.exe
tdx.sys
afd.sys
cdrom.sys
i8042prt.sys
netbt.sys
redbook.sys

mrxsmb.sys

/md5stop

hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs


 

Press the 

 

 

An OTL.txt will be created.

 

Quads

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

Re: Trojan rootkit A.........

okay,  I have the text.     What do I do now?    Attach it ?

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Trojan rootkit A.........

Yes

 

Quads

Contributor
jeff_wa_40
Posts: 17
Registered: ‎06-08-2012

Re: Trojan rootkit A.........

here it is.