Reply
Contributor
APO132400
Posts: 10
Registered: ‎08-24-2009
Accepted Solution

NIS09: Full system scan shows "0" files scanned

[ Edited ]

Hi im currently running Norton.I.S 2009 and a few days ago i went to do a weekly full system scan on my computer. I left it running for an hour and came back to it and it had not scanned any file at all; no files scanned, no threats etc. All of the digits showing were at 0. I am inneed ofsome help please!

 

I think i have a rootkit located in my computer (after looking at some other comments, but the solutions were not shown publicly) which has bypassed the software some how; is there any way i can remove this etc as now i am unable to scan my computer for viruses etc and haven't been for the last week or so.

 

Thanks in advance!

 

I have also uploaded a file which might of help as well...

 

<<Edit: Edited subject for clarity>>

Message Edited by TomV on 08-24-2009 10:50 PM
Contributor
APO132400
Posts: 10
Registered: ‎08-24-2009

Re: Norton Internet Security 2009

[ Edited ]

As far as i know there is no other anti virus software or anything similar conflicting with norton or installed on my computer...The version of Norton i am using is as follows:-

 

Norton Internet Security 2009 - - -  Version 16.0.0.125

 

Any help would be much appreciated!

 

 

I dont know if it is required to be off but my norton auto protect was on when i ran the log...Here is it when the auto protect was off, sorry!

Message Edited by APO132400 on 08-25-2009 03:06 AM
dbrisendine
Posts: 5,562
Kudos: 1,282
Solutions: 263
Registered: ‎10-06-2008

Re: Norton Internet Security 2009

How long have you had Norton?

 

You have a new Rootkit (actually two) on your system.  Please be patient.  There are others in line ahead of you right now.

Contributor
APO132400
Posts: 10
Registered: ‎08-24-2009

Re: Norton Internet Security 2009

Hello dbrisendine, thank you for replying to my situation! I have had N.I.S 2009 for less than a year, my subscription ends in 120 days or so. I installed it onto my computer christmas 2008, only recently about 2 months ago re-installed it due to the fact i was doing a hard drive format.

 

Can these be dealt (removed) with btw?

 

 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Norton Internet Security 2009

APO132400:

 

They can be dealt with provided you follow the instructions given to you by Quads, who is our guru qualified for these removals. He has been advised.  If you have used any other software to try and remedy the situation yourself, please advise us now.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Contributor
APO132400
Posts: 10
Registered: ‎08-24-2009

Re: Norton Internet Security 2009

I have used nothing to resolve these issues, i only found out 1 or 2 days ago and i am only 16 (i own and is the admin of the computer). I know nothing about these "rootkits".
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Norton Internet Security 2009

Hi

 

I have sent you a personal message, look for the yellow envelope on the upper right hand side

 

Quads 

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Norton Internet Security 2009

Hi

 

Continuation of Stage 1,  File removal

 

Now the registry entries will be greyed out I think, will get them later.

 

Tick (check) these entries (little square box beside each entry) Only the entries below, not the others

 


C:\Windows\Temp\kbiwkmcdbnsluoos.tmp

C:\Windows\System32\kbiwkmmtpwnyor.dll

C:\Windows\System32\kbiwkmcqxiuorf.dat

C:\Windows\System32\kbiwkmnwtcigqr.dll

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmsuwhohcqpn.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpvuwisfqwx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmrnxsbwcxgx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwxdgqevqvx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmrmwmjeyysj.tmp

C:\Users\MUM\AppData\Local\Temp\Low\kbiwkmrpopyqruwm.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpsnunglujc.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmoxtcqwbinp.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwwtrhluise.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmibdbxfqqyy.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqisrieskme.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmklxdvosopp.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmmmrtqfnkej.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbhtkucclit.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfhsgocaimn.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmeixiklbnpi.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmiesrihoeic.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxpioufnhws.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmsviurmesbk.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcytfpbumuc.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmatbxqijynh.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnipdxrdcej.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtqurinnciy.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbgcsscpfye.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmswuvujpgqe.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmctwwwgodcg.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqeprlwfner.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxmixgydqgm.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdvkecqvfcm.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmvqbprjrqtx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxxpwrjlbjh.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcgdnqoulgk.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmaeovgylkoa.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqxnpeinhpq.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhvmagdqepq.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmbiurytrklo.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhvfqkvsrby.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmuqtjcvcqgx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmleygbxekhw.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmvgofcvyvsg.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqbgogtsydm.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdnweahroks.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhwcrxmtxjl.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtrhqavdodg.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnydpprvtyf.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmdvxyystqtw.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmppnqtroxfp.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfirqnttyhh.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtpsqkdcqlr.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcqtjnosuhh.tmp

C:\Windows\System32\kbiwkmxvihiowm.dat

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtpaemikoxb.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhavqrdpcyc.tmp

C:\Windows\System32\kbiwkmxomiwjve.dat

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmjhngfvkusi.tmp

C:\Windows\System32\drivers\kbiwkmypcscnrx.sys

C:\Windows\System32\drivers\kbiwkmuhmqciqp.sys

C:\Windows\System32\kbiwkmhxkmyhpb.dll

C:\Windows\System32\kbiwkmiurqsspt.dll

C:\Windows\System32\kbiwkmbwwvaxuu.dat

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmxbttaecsew.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmmuaqeetovn.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmdouitqekgr.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmhrbulxoapl.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmtqxcgebtin.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmkkigjslxnn.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmcwsnrdpmph.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmlyjopwgcri.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmxyjxffnlmt.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmahjedqdfew.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmojebcljjbb.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmspsqjjxuki.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmflwboxiuix.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmqkfmvibtux.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmiaptxysnll.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmoyhanuflqy.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmwcysjucplf.tmp

C:\Users\APOSTOLIS\AppData\Local\Temp\Low\kbiwkmvedjlspsqa.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmnukdekhuue.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmwtrpeesybg.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmgdynhtjafx.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmfxuxhpyvdj.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmganawvnjsv.tmp

C:\Users\GEORGINA\AppData\Local\Temp\Low\kbiwkmpbnjtqinof.tmp

C:\Users\MUM\AppData\Local\Temp\Low\kbiwkmtpngiyeeui.tmp 



Then click the Clean items button

Follow the prompts to remove them and restart your computer.

After reboot, a dialog box displays the files you selected for removal and the action taken.

 

Step 2 after 

 

 

Quads 

Contributor
APO132400
Posts: 10
Registered: ‎08-24-2009

Re: Norton Internet Security 2009

[ Edited ]

Hi Quads, i have done what you asked and rebooted the computer. All of the files have been successfully removed! Shown through the dialog box that came up. Am i ready for step 2 yet? Thank you for your time...

Message Edited by APO132400 on 08-25-2009 06:02 AM
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Norton Internet Security 2009

Did you do this

 

Then click the Clean items button

Follow the prompts to remove them

 

Quads