Reply
Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012
Accepted Solution

Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

Hoping someone can help.  I keep getting messages similar to this: 

Scan type: Auto-Protect Scan
Event: Security Risk Found!
Security risk detected: Trojan.Gen.2
File: C:\Windows\Installer\{a54b25a2-2196-0a20-fab7-cb13bc4924cd}\U\80000032.@
Location: Quarantine
Computer:
User: SYSTEM
Action taken: Quarantine succeeded : Access denied
Date found: Wednesday, May 30, 2012 10:30:19 PM

 

I have tried a full scan with Symantic antivirus as well as the downloadable rootkit tool from nortan, but I keep getting the same messages every time I restart.  Any ideas?

Bot Obliterator
Quads
Posts: 13,241
Registered: ‎07-21-2008

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

What is your Windows, including 32 or 64 bit??

 

Quads

Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

I have windows 7 64bit

Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

I get a new set of messages about Trojan.Gen.2 and Hacktool.Rootkit around every 5 minutes.  At the same time Malwarebites blocks something trying to access outside IP addresses.

Bot Obliterator
Quads
Posts: 13,241
Registered: ‎07-21-2008

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

Malwarebytes Realtime and Norton together is a NO.

 

Quads

Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

ok, I stopped malewarebytes but I am still recieving the massages from symantec.  Thank you for replying Quads.  I just read a post that you helped another user with a similar issue.  I'm afraid to try running the things you suggested though because of all the warnings.

 

dibrown

Bot Obliterator
Quads
Posts: 13,241
Registered: ‎07-21-2008

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

C:\Users\t[username]\AppData\Local\{[Numbers]}

C:\WINDOWS\Installer\{[Numbers]}

 

The numbers are the same for both locations, Norton has detected one   I need the username one is under.

 

Quads

Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

my user name is David.  I can't seem to find the numbers file in the directory you mentioned.  Is it hidden somehow?  Thanks.

 

dibrown

Bot Obliterator
Quads
Posts: 13,241
Registered: ‎07-21-2008

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

Is your system set to show hidden files and folders etc.??

 

It may be under / in someone elses user account.

 

Quads

Contributor
dibrown
Posts: 32
Registered: ‎05-30-2012

Re: Recurring Trojan.Gen.2 and Hacktool.Rootkit Messages

I can't find it in any user account.  I only have my own, Default and Public.  I verified that hidden files and folders are visible.  I tried typing it directly into explorers toolbar and it was not found.