Link to home
Start Free TrialLog in
Avatar of SCDL
SCDL

asked on

Trojan removal download recommendation

Yesterday some users on our network had their McAfee disabled and this morning I ran Malicious Software Removal tool from microsoft and found Malware on my computer named Backdoor:Win32/Qakbot.gen!B (partially removed) and TrojanDownloader:JS/Qakbot.F that was removed.  It recommended that I run my McAfee but I cannot get it to run, I think the Trojan disabled it?  Can you recommend any downloads I can try to fix our infected computers?
Avatar of bwinkworth
bwinkworth
Flag of Canada image

Sometimes I'll resort to free online scanners. Bitdefender has one and so does trendmicro. After that I'll run hijackthis to see if there's any entries in the registry.

BW
Avatar of Rob Knight
Hi,

You could load this:

http://service.mcafee.com/SpecializedServiceHome.aspx?lc=2057&sg=VR

Regards,


RobMobility.
SOLUTION
Avatar of Rob Knight
Rob Knight
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of SCDL
SCDL

ASKER

Thanks everyone for your advice.  Hapexamendios you were correct in that it had a kernel-mode driver installed by the trojan. Our 350 pc's and handful of servers were removed from the network Friday morning so I did not see the last 2 comments until after we were back up.  The trojan also disabled McAfee and prevented us from downloading solutions or recover to a previous time. Hapexamendios and Madunix you were both correct in suggesting using CD's to eliminate this nasty trojan which shall remain nameless to prevent notoriety.  McAfee created a program for us directly to eliminate it and after working thru the weekend we were 98% back up by Monday afternoon. Thanks RobMobility and bwinkworth for your quick replies but I would have been a goner without the cd's. Running Stinger was a step in the final solution so I would like to award points for that too, RobMobility.
Glad you got it all fixed up fella.

Regards,
BW
Avatar of SCDL

ASKER

I did not get a chance to actually try  Hapexamendios and Madunix suggestions so they may also have worked.
TThanks for the credit, SCDL - a pleasure to help, and as you say it looks like you took our advice without even knowing it! :)

I'd just like to add to this post, for anyone coming to it in the future, to remember that if you have an AV product with support, they probably have a way of making a bootable CD available for you to use upon request, and in most cases that will be the simplest way to sort this kind of issue.

Peace, all