Hey everyone! Could someone please help me out? I, like many others it seems, keep getting Trojan.Gen.2 and Hacktool.Rootkit messages about every 5-10 minutes. Could someone help me solve this?
I have a Windows Vista, 64-bit. I have Norton 360.
Hey everyone! Could someone please help me out? I, like many others it seems, keep getting Trojan.Gen.2 and Hacktool.Rootkit messages about every 5-10 minutes. Could someone help me solve this?
I have a Windows Vista, 64-bit. I have Norton 360.
Welcome,
Sorry we're meeting under these circumstances. I can recommend only two solutions. The first is to wait for user, volunteer Quads to see your message and respond. The other is to go to one of the sites listed below and work with only one of their experts. The rule is the same in all cases. You finish with the one that started the process. It is individual and please, no self-help fixes while you wait. They will only complicate the process.
The links
http://www.bleepingcomputer.com
http://www.geekstogo.com/forum/
http://www.cybertechhelp.com/forums/
http://forums.whatthetech.com/
Thanks
Moved to own thread for better exposure.
Which option are you taking??
Quads
I'd love it if you could help me Quads!
I have a flash drive, too. Thank you so much in advance!
Now my Norton is also blocking Trojan zeroaccess.
Norton told me I had to restart my computer in order to finish removing threats. I restarted my computer. After it restarted, I tried to open up Norton again to run a quick scan. All of a sudden, Norton closed and the icon at the bottom right-hand corner of the screen disappeared. I shut my computer down in fear of not having Norton running anymore and I am now using my friend's computer to type this.
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
Do you have a Flash Drive??
Quads
Yes I do have a flash drive.
Now instead of saying "blocked" next to all of the trojan and hacktool notifications, it says "pending" a lot.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ Download the 64 bit version
Transfer it on to the Flash Drive
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
I attached the text file.
Step 2
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
Fixlog is attached.
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-virus/combofix
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
I am having trouble disabling my Norton 360 Antivirus. I was able to disable the firewall, but the antivirus keeps keeps coming back on because I keep getting a message that says "Restart Required: Your computer must restart in order to continue the removal of Security Risks." I selected "Remind me again in 1 hour", but then my Antivirus comes back on and I cannot disable it (the "disable antivirus" button is greyed out). This keeps happening over and over again. Should I run combofix with the Antivirus on? Or is there something I can do?
The threat that keeps prompting me to restart my computer is Trojan.Gen.2. The file that is infected is c:\Windows\assembly\GAC_64\Desktop.ini
EDIT: This time it was a zeroaccess that made me restart my computer again.
Run Combofix in safe Mode.
Quads
I cannot disable Norton 360 in safe mode. All I can do is run a full system scan. When I tried to run combofix, a warning popped up saying I still have Norton 360 Antivirus and Norton 360 Antispyware still running. What should I do?
You don't need to in Safe Mode as Realtime Protection does not run.
Just run combofix in safe mode, If Combofix restarts the system make sure to go back into safe mode
Quads
I think I ran into a problem while running combofix. I’m in safe mode. I ran combofix as an administrator. It got up to “Completed Stage 50” and then it said "System file is infected !! Attempting to restore C:\Windows\system32\Services.exe and then it stopped. It’s been like this for about a half an hour now. I did not click on the screen at all. I do not think it froze because there is still a flashing underscore under the last message.
Please disregard my previous post. Combofix eventually finished running after an hour. I attached the log.