Author Topic: Got Zapped By Hiberfil.sys Rbot Trojan  (Read 4442 times)

0 Members and 1 Guest are viewing this topic.

Nesivos

  • Guest
Got Zapped By Hiberfil.sys Rbot Trojan
« on: December 26, 2012, 10:04:13 PM »
Current status.

1. Tried reinstalling W7 on a freshly formatted HDD with only one drive -  Hangs on BSOD after starting "Services"
2. Tried to reboot in Safe Mode.  Message said I could reboot in Safe Mode as Windows had not completed installation.
2. Ran avast! Rescue disk.   It found Hiberfil.sys on "D" drivve.  The avast! Rescue disk could not delete, move or rename the file.
3. Stuck

Any ideas on how to get rid of Hiberfil.sys.

Thanks

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #1 on: December 26, 2012, 11:05:29 PM »
Quote
Any ideas on how to get rid of Hiberfil.sys.
i guess you have been here long enough to know what essexboy need  ;)
« Last Edit: December 26, 2012, 11:10:36 PM by Pondus »

Nesivos

  • Guest
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #2 on: December 27, 2012, 02:37:38 AM »
Quote
Any ideas on how to get rid of Hiberfil.sys.
i guess you have been here long enough to know what essexboy need  ;)

Actually No

However, I can provide nothing since the OS won't boot

Win 7-SP1 x64
Hiberfile.sys Rbot Trojan

That is all I can provide.   Other than that nothing.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #3 on: December 27, 2012, 02:39:20 AM »
so you haven't seen this before ?

http://forum.avast.com/index.php?topic=53253.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #4 on: December 27, 2012, 03:16:51 AM »
so you haven't seen this before ?

http://forum.avast.com/index.php?topic=53253.0

That won't help unless you can get the system to boot.

@ Nesivos
I think that the Hiberfile.sys and pagefile.sys can on occasion end up with some weird strings that may well be identified as malware. When you eventually manage to get back in to the OS disable hibernation and delete the Hiberfile.sys file. You can then enable hibernation again. What is on the D: drive if nothing that hasn't been backed up perhaps you could format that also before trying a format of c: and reinstall of win7. Or using a linus lice CD and see if you can find and remove the d:\Hiberfile.sys file.

Are you not able to do a Repair Install in win7, but since you have just done reinstall on a freshly formatted drive and ended up with a bsod. I don't if a repair install is likely to be able to cut it.

When you reinstalled after a format, did the installation complete and you reboot successfully before installing avast ?

In your first post you said "Message said I could reboot in Safe Mode as Windows had not completed installation." I take it you meant that you couldn't reboot in Safe Mode ?

If that is, that you couldn't reboot in Safe Mode as Windows had not completed, it looks like a corrupt installation.

That's me for the night almost 2:20am here, but you also need someone more familiar with this type of thing 'essexboy' as he has revived many a dead system. But it is no easy task.
« Last Edit: December 27, 2012, 03:18:29 AM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #5 on: December 27, 2012, 10:17:28 AM »
So the actual install has failed..  First option would be to run a fresh install formatting the disc first
If that again fails, is the system 32 or 64 bit

Nesivos

  • Guest
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #6 on: December 29, 2012, 10:25:17 PM »
So the actual install has failed..  First option would be to run a fresh install formatting the disc first
If that again fails, is the system 32 or 64 bit

I tired several times with several registerd W7 DVDs.   No luck.

So I decided the following.

1.  I upgraded my two working desktops to W8-Pro since I have two registered DVD's for W8-Pro
2.  I then converted the computer that wouldn't install W7 to Ubuntu.  I have used Ubuntu on and off for years so I was comfortable doing this.  I had no problems intalling Ubuntun 12.10 on the computer that would not install W7 and which the avast! Rescue Disk indicated that HIberfil.sys in W7 was infected.  I did a clean install of Ubuntu after reformatting the disk.   Everything is working fine. 
3.  Since avast! has had a number of issues with W8 I decided to use Windows Defender on the two computers that I upgraded to W8-Pro. 
4.  I then installed a trial version of Malwarebytes Pro on the two W8 computers.   No problem there.
5.  Then after I made the OP on this subject I noticed that Bitdefender had released a new product Bitdefender AV Free which Bitdefender says is compatible with W8.   During the installaton process of Bitdefender AV Free it disabled Windows Defender.  Windows 8 had no problem with this. However, during the isntallation of Bitdefender AV Free it did a forced uninstall of Malwarebytes Pro.   I have contacted both Bitdefender and Malwarebytes about this and await an answer.

So as it stands now I am not using any avast! products on my three computers.   At some point I may reinstall avast! AIS on the two computers that now have Bitdefender AV Free on them and then reinstall Malwarebytes Pro.   However, at this time due to the numerous issues regarding using avast! 7 on W8 I will continue to use Bitdefender AV Free.

Thanks for your help on this. :)


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Got Zapped By Hiberfil.sys Rbot Trojan
« Reply #7 on: December 29, 2012, 10:29:13 PM »
unless there is something new....Bitdefender free does not have real time protection....it is on demand scan only