08-24-2009 06:35 PM - last edited on 08-24-2009 10:50 PM by TomV
Hi im currently running Norton.I.S 2009 and a few days ago i went to do a weekly full system scan on my computer. I left it running for an hour and came back to it and it had not scanned any file at all; no files scanned, no threats etc. All of the digits showing were at 0. I am inneed ofsome help please!
I think i have a rootkit located in my computer (after looking at some other comments, but the solutions were not shown publicly) which has bypassed the software some how; is there any way i can remove this etc as now i am unable to scan my computer for viruses etc and haven't been for the last week or so.
Thanks in advance!
I have also uploaded a file which might of help as well...
<<Edit: Edited subject for clarity>>
Solved! Go to Solution.
08-24-2009 06:42 PM - edited 08-24-2009 07:06 PM
As far as i know there is no other anti virus software or anything similar conflicting with norton or installed on my computer...The version of Norton i am using is as follows:-
Norton Internet Security 2009 - - - Version 16.0.0.125
Any help would be much appreciated!
I dont know if it is required to be off but my norton auto protect was on when i ran the log...Here is it when the auto protect was off, sorry!
08-24-2009 07:19 PM
How long have you had Norton?
You have a new Rootkit (actually two) on your system. Please be patient. There are others in line ahead of you right now.
08-24-2009 07:23 PM
Hello dbrisendine, thank you for replying to my situation! I have had N.I.S 2009 for less than a year, my subscription ends in 120 days or so. I installed it onto my computer christmas 2008, only recently about 2 months ago re-installed it due to the fact i was doing a hard drive format.
Can these be dealt (removed) with btw?
08-24-2009 07:44 PM
APO132400:
They can be dealt with provided you follow the instructions given to you by Quads, who is our guru qualified for these removals. He has been advised. If you have used any other software to try and remedy the situation yourself, please advise us now.
08-24-2009 07:47 PM
08-24-2009 07:53 PM
Hi
I have sent you a personal message, look for the yellow envelope on the upper right hand side
Quads
08-24-2009 09:38 PM
Hi
Continuation of Stage 1, File removal
Now the registry entries will be greyed out I think, will get them later.
Tick (check) these entries (little square box beside each entry) Only the entries below, not the others
C:\Windows\Temp\kbiwkmcdbnsluoos.tmp
C:\Windows\System32\kbiwkmmtpwnyor.dll
C:\Windows\System32\kbiwkmcqxiuorf.dat
C:\Windows\System32\kbiwkmnwtcigqr.dll
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmsuw
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpvu
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmrnx
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwxd
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmrmw
C:\Users\MUM\AppData\Local\Temp\Low\kbiwkmrpopyqru
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpsn
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmoxt
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwwt
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmibd
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqis
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmklx
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmmmr
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbht
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfhs
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmeix
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmies
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxpi
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmsvi
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcyt
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmatb
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnip
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtqu
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbgc
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmswu
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmctw
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqep
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxmi
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdvk
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmvqb
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxxp
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcgd
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmaeo
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqxn
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhvm
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbiu
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhvf
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmuqt
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmley
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmvgo
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqbg
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdnw
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhwc
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtrh
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnyd
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdvx
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmppn
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfir
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtps
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcqt
C:\Windows\System32\kbiwkmxvihiowm.dat
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtpa
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhav
C:\Windows\System32\kbiwkmxomiwjve.dat
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmjhn
C:\Windows\System32\drivers\kbiwkmypcscnrx.sys
C:\Windows\System32\drivers\kbiwkmuhmqciqp.sys
C:\Windows\System32\kbiwkmhxkmyhpb.dll
C:\Windows\System32\kbiwkmiurqsspt.dll
C:\Windows\System32\kbiwkmbwwvaxuu.dat
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmxb
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmmu
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmdo
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhrb
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtqx
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmkki
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcws
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmlyj
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxyj
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmahj
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmoj
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmsp
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmfl
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqkf
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmiap
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmoyh
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmwc
C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmve
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnuk
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwtr
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmgdy
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfxu
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmgan
C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpbn
C:\Users\MUM\AppData\Local\Temp\Low\kbiwkmtpngiyee
Then click the Clean items button
Follow the prompts to remove them and restart your computer.
After reboot, a dialog box displays the files you selected for removal and the action taken.
Step 2 after
Quads
08-24-2009 09:59 PM - edited 08-24-2009 10:02 PM
Hi Quads, i have done what you asked and rebooted the computer. All of the files have been successfully removed! Shown through the dialog box that came up. Am i ready for step 2 yet? Thank you for your time...
08-24-2009 10:02 PM
Did you do this
Then click the Clean items button
Follow the prompts to remove them
Quads
