Trojan.FakeAV!gen6
Yea umm, I'm not to tech savvy so could you please go slow on this and not use big words...
So yesterday I was just surfing the internet and this risk thing came up saying that these tojan.jake things were on my computer. So I thought, no big deal since the report said that she were low security risks and endpoint removed them for me. But then 45 minutes later when I was doing something on my ipod, but not on the computer, the same window popped up again, with the same name, but in a different file. But it was still in the same folder. And its every 45 minutes that another one pops up, if I'm on the internet or not. Is it just going to keep doing this or is there something I can do? I was going to contact symantec but they don't have a live chat or anything and I don't want to email them.
So is there a way to get rid of this thing? I already ran a full scan twice and nothing poped up, just cookies.
You can see in the attached picture how many times its come up...
Thanks for your help
Comments
please help people..
please help people..
Hi crazypotatos, First I just
Hi crazypotatos,
First I just want to make sure you are actually using SEP and not a Norton product. The only reason I say this is because it sounds like you are a home user and that makes me think you might actually be running one of the Norton products like 360. If that is the case please visit their site here to post: http://community.norton.com/norton/.
If you are really using SEP then you should do a full scan in safe mode with system restore off. This is better than just a full scan.The full details of this can be found in this guide: http://service1.symantec.com/support/ent-security..... Hopefully this solves your issue.
If that does not find the virus then you should submit the file to symantec. We can then analize it and incorporate it into the next rapid release definition. Details on how to submit the file to symantec are here: http://service1.symantec.com/support/ent-security..... After that you should then apply the latest rapid release definition to your computer. Details of that are found here: http://service1.symantec.com/support/ent-security.....
If any of this was confusing please don't hesitate to post back or pm me. Just as a side note you should also try to tell where/how you got the virus. For instance did you visit any questionable sites, or use torrent clients lately? Not that it matters too much, but it might help you to identify where you got the virus so you can attempt to not fall into that same trap again.
Cheers
Grant
Please don't forget to mark your thread solved with whatever answer helped you : )
Yes is is endpoint. My
Yes is is endpoint. My neighbor is a computer saleman and he has the business pack thing. I'll try what you said and I'll reaspond back in the morning when this is done.
How do I turn off system restore? I found a thing on microsoft's website but it said it was going to delete stuff or something. And how do I put it into safe mode?
Sorry, that guide didn't really tell me what you explained.
No its ok. Follow these steps
No its ok. Follow these steps taken from microsofts site to turn off system restore:
After a few moments, the System Properties dialog box closes.
Now you can see that in step 5 it warns that this will delete all of your former restore points. Actually this is exactly what we want to do. The problem is that viruses can hide themselves in the system restore so if you don't turn it off it can "restore" itself again and again. So this is why we have you turn off system restore. Also to boot into safe mode please restart your computer and immediately start pressing F8. You will be prompted with a number of different options to boot to. Select safe mode. After you get into safe mode turn the system restore off and then do a full system scan. The full system scan in safe mode is identical to the full system scan regularly.
Hope this is a little clearer,
Grant
Please don't forget to mark your thread solved with whatever answer helped you : )
Just to help explain why new
Just to help explain why new files appear even while you're not using the computer. Malware often tries to download and install additional malware, which is probably why you were getting regular warnings. So there is an infection on your computer that is grabbing these files.
Eric C. Lukens IT Security Policy and Risk Assessment Analyst University of Northern Iowa
Ok so while I was at school,
Ok so while I was at school, i did the full scan on safe mode and with system restore off. While the scan didn't find anything, SEP isn't finding it automatically. Ill notify you if it comes up again. I also unplugged my ethernet cable while the scan was going.
Ug great. Its back again. I
Ug great. Its back again. I think it may be from this one site, although I'm not sure...
I'm gonna try to remove it again later today...
@Crazypotatos Any updates on
@Crazypotatos
Any updates on how its going?
Eric C. Lukens IT Security Policy and Risk Assessment Analyst University of Northern Iowa
Ok I got rid of the actual
Ok I got rid of the actual trojan, but now whenever I click on a link on google, anyother random site pops up. It happens 75% of the time. I downloaded Malwarebytes's anti-malware to remove it, but when I "remove" it, it just keeps coming back. Its really annoying since I am a student.
SEP doesn't detect this thing though.. and I don't know where the orginal file and folder is where it is located.
Help please
Additional Advice
Hi Crazypotatoes,
If posssible, please submit those files which keep coming back to Security Response. They will perform an analysis on them and update the definitions used to detect and remove such threats. Many of the hundreds of detections added daily are created in response to submissions from Symantec customers.
Symantec Technical Support have tools similar to the one you used which can help identify any additional suspicious files.
I also recommend running a "disk cleanup"- anything malicious in your temp locations willl be deleted. Plus, make sure that your MS patches are fully up to date.
Hope this helps!
Thanks and best regards,
Mick
With thanks and best regards,
Mick
I would, but on my
I would, but on my Malwarebytes thing, it says HKEY something something. I don't know where that is.
Ill run a disk cleanup today.
I just ran the disk cleanup
I just ran the disk cleanup and it didn't do anything. it just got rid of some old files. Do you mean that error checking thing?
Would you like to reply?
Login or Register to post your comment.