Hi There,
I am helping my friend with her laptop and based on reading the posts on this website we think there is a trojan on it.
C:\windows\system32\services.exe is trying to access Norton's ccsvchst.exe.
The services.exe file is under C:\windows\system32
And there is a services file in another directory:
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b
The following files are in this folder:
services.mof
services.ptxml
Can you please help us solve our problem?
Thank you.
Hi There,
I am helping my friend with her laptop and based on reading the posts on this website we think there is a trojan on it.
C:\windows\system32\services.exe is trying to access Norton's ccsvchst.exe.
The services.exe file is under C:\windows\system32
And there is a services file in another directory:
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b
The following files are in this folder:
services.mof
services.ptxml
Can you please help us solve our problem?
Thank you.
I've ran the recovery scan tool to get started. Attached is the text file from it.
I think we have the same virus trojan as the person who started the thread:
Re: REcovering Trojan.Gen.2 & Hacktool.rootkit Messages.
Can someone help?
yank
August 3, 2012, 8:14pm
5
Hi netdefender22 and ghosty,
I suggest neither of you do any more to the systems involved until Quads gets here and decides what to do with your situations - as he would probably say Pass or Play! You may have already done too much for him to Play - so please do not make run anything else on your system or make any more changes inorder to enhance your chance of getting it cleaned up.
I have not done anything except what I have notified you about. I know we are not supposed to as each system is not the same as another. Please help. Thank you.
Quads
August 4, 2012, 6:36am
7
I am not doing anything, use advanced programs and ignore warnings. Have a nice play.
People know what Unauthoriz ed Access Blocked is for anyway
Quads