September 6, 200916 yr A couple days ago, I was helping someone out and downloaded a keygen for them. Now, every time I turn on my computer, the keygen pops up and Windows defender gives me a warning about "Backdoor:Win32/Rbot.gen!G". I don't know what to do. :c
September 6, 200916 yr Your AV can't remove it? And what's your AV? J'adore aussi le sexe et les snuff moviesJe trouve que ce sont des purs moments de vieJe ne me reconnais plus dans les gensJe suis juste un cas désespérantEt comme personne ne viendra me réclamerJe terminerai comme un objet retrouvé
September 6, 200916 yr Have you tried running Avira and see if it can delete it? Otherwise what i found was a solution at Sophos, but that includes going into the registry ( http://www.sophos.com/security/analyses ... botwv.html ). If you can, wait for someone else to give you a better reply. J'adore aussi le sexe et les snuff moviesJe trouve que ce sont des purs moments de vieJe ne me reconnais plus dans les gensJe suis juste un cas désespérantEt comme personne ne viendra me réclamerJe terminerai comme un objet retrouvé
September 6, 200916 yr Author I've had Avira run a scan, but it doesn't pick anything up. Thanks for the link, it'll be helpful if no one else has any advice, but I'll wait a little bit for more replies.
September 7, 200916 yr The solution to your problem. [*:1gc7avnh]Make a virtual machine [*:1gc7avnh]Install your OS on to the virtual machine [*:1gc7avnh]Snapshot the hard drive [*:1gc7avnh]Download Trojans on to your virtual machine [*:1gc7avnh]Snapshot the hard drive [*:1gc7avnh]Compare snapshots [*:1gc7avnh]Using information, remove Trojan from actual machine [*:1gc7avnh]Never download shifty programs on to your actual machine again - that is what virtual machines are for - installing viruses and having nothing happen Of course that is not guaranteed to work (the Trojan may perform different actions depending on the date and time or your system's configuration), but has a very high chance of. Never trust anyone. You are always alone, and betrayal is inevitable.Nothing is safe from the jaws of the decompiler.
September 8, 200916 yr Since Sunbelt Labs has an entry on the named Trojan, and its advice is to use Remove, Sunbelt Home and Home Office antivirus might be able to remove it. Or look for "Backdoor:Win32/Rbot.gen!G removal tool" on Google :) Jard, while your instructions are top-notch for those who want to submit infection samples to an antivirus lab (i.e. IT security experts), I don't expect average users to be able to do this. :|
September 8, 200916 yr Author Since Sunbelt Labs has an entry on the named Trojan, and its advice is to use Remove, Sunbelt Home and Home Office antivirus might be able to remove it. Or look for "Backdoor:Win32/Rbot.gen!G removal tool" on Google :) Jard, while your instructions are top-notch for those who want to submit infection samples to an antivirus lab (i.e. IT security experts), I don't expect average users to be able to do this. :| Thanks for that link and I didn't even think about just searching on Google lol. #-o
September 8, 200916 yr Keygens will always be classified on AV's as trojans/viruses because they generate code - at least most of them time, it depends where you download stuff from. 2257AD.TUMBLR.COM
September 9, 200916 yr Author Keygens will always be classified on AV's as trojans/viruses because they generate code - at least most of them time, it depends where you download stuff from. I used to always scan my files after I downloaded them, but I've pretty much stopped that since I got a Demonoid invite. Guess I shouldn't have. Since Sunbelt Labs has an entry on the named Trojan, and its advice is to use Remove, Sunbelt Home and Home Office antivirus might be able to remove it. Or look for "Backdoor:Win32/Rbot.gen!G removal tool" on Google :) Jard, while your instructions are top-notch for those who want to submit infection samples to an antivirus lab (i.e. IT security experts), I don't expect average users to be able to do this. :| The Sunbelt AV is only a trial, so I ran a search and there was a removal tool on Microsoft's website, but IE crashed while it was running. -.- I'm gonna try it again today in safe mode, but if it doesn't work I'll just download the trial.
September 9, 200916 yr Keygens will always be classified on AV's as trojans/viruses because they generate code - at least most of them time, it depends where you download stuff from. They're actually generally classified as viruses because of the packers they use to contain themselves, which is similar to the same packing that some viruses use. It's because of the way they are contained, not because of their function.
Create an account or sign in to comment