Computing.Net > Forums > Security and Virus > Generic Downloader.f & many more

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Generic Downloader.f & many more

Reply to Message Icon

Name: com1jay
Date: February 21, 2007 at 08:11:58 Pacific
OS: XP
CPU/Ram: 256MB
Product: eMachines
Comment:

My computer is infected with multiple visruses which do not go away after mcafee scan. I ran mcafee in SAFE mode in DOS and it says it cleaned a bunch of viruses/trojans (please see the log). When I reboot in normal mode, viruses/trojans reappear and in also replicate too many times. I also had run tune-up! registry fix after mcafee scan but that does not seem to help. Attaching the log from mcafee scan and I have HijackThis log I got after I rebooted in normal mode (can provide the log if you need).
================= begin of McAfee scan log ============
McAfee VirusScan for Win32 v5.10.0
Copyright (c) 1992-2006 McAfee, Inc. All rights reserved.
(408) 988-3832 LICENSED COPY - May 26 2006

Scan engine v5.1.00 for Win32.
Virus data file v4967 created Feb 20 2007
Scanning for 230136 viruses, trojans and variants.

02/20/2007 23:43:33


Options:
C:\WINDOWS /ADL /CLEAN /ALL /REPORT REPORT.TXT

Scanning C: []
Scanning C:\WINDOWS\*.*

Summary report on C:\WINDOWS\*.*
File(s)
Total files: ........... 287
Clean: ................. 287
Possibly Infected: ..... 0
Cleaned: ............... 0
Scanning C: []
Scanning C:\*.*
C:\Documents and Settings\Owner\Local Settings\Temp\1.dllb ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\Documents and Settings\Owner\Local Settings\Temp\5.dllb ... Found the W32/Zhelatin.gen.b@MM virus !!!
The file has been deleted.
C:\Documents and Settings\Owner\Local Settings\Temp\qv3xt3.game ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\Documents and Settings\Owner\Local Settings\Temp\qvxt34.game ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\Documents and Settings\Owner\Local Settings\Temp\qvxt42.game ... Found the Tibs trojan !!!
The file has been deleted.
C:\Documents and Settings\Owner\Local Settings\Temp\win9868.tmp\win9868.tmp ... Found the BackDoor-CXJ trojan !!!
The file has been deleted.
C:\Program Files\Common Files\{1417BE8B-0A1F-1033-0916-031025200001}\Update.exe ... Found the Generic Downloader.k trojan !!!
The file has been deleted.
C:\Program Files\Common Files\{3417BE8B-0A1F-1033-0916-031025200001}\Bar888.dll ... Found the Matcash.dll trojan !!!
The file has been deleted.
C:\RECYCLER\S-1-5-21-2105242733-1762407506-2985652280-1003\Dc1\Update.exe ... Found the Generic Downloader.k trojan !!!
The file has been deleted.
C:\RECYCLER\S-1-5-21-2105242733-1762407506-2985652280-1003\Dc2\Update.exe ... Found the Generic Downloader.k trojan !!!
The file has been deleted.
C:\WINDOWS\system32\adir.dll ... Found the Downloader-ZQ trojan !!!
The file has been deleted.
C:\WINDOWS\system32\dlh9jkd1q1.exe ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\WINDOWS\system32\dlh9jkd1q5.exe ... Found the W32/Zhelatin.gen.b@MM virus !!!
The file has been deleted.
C:\WINDOWS\system32\inet.exe ... Found the Tibs trojan !!!
The file has been deleted.
C:\WINDOWS\system32\qvx5gamet2.exe ... Found the Tibs trojan !!!
The file has been deleted.
C:\WINDOWS\system32\qvxga6met3.exe ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\WINDOWS\system32\qvxga7met4.exe ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\WINDOWS\system32\unsvchosts.exe ... Found the Matcash trojan !!!
The file has been deleted.
C:\WINDOWS\system32\vxga1me4t1.exe ... Found the W32/Zhelatin.gen.b@MM virus !!!
The file has been deleted.
C:\WINDOWS\system32\vxga3me2.exe ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\WINDOWS\system32\vxga4m1et4.exe ... Found the Generic Downloader.f trojan !!!
The file has been deleted.
C:\WINDOWS\system32\vxga4me1.exe\00001060.EXE\00001060.exe ... Found the BackDoor-CXJ trojan !!!
The file has been deleted.
C:\WINDOWS\system32\wincom32.sys ... Found the Downloader-BAI.sys.gen trojan !!!
The file has been deleted.

Summary report on C:\*.*
File(s)
Total files: ........... 74855
Clean: ................. 74744
Possibly Infected: ..... 23
Cleaned: ............... 0
Deleted: ............... 23
Non-critical Error(s): 1
Master Boot Record(s): ......... 1
Possibly Infected: ..... 0
Boot Sector(s): ................ 1
Possibly Infected: ..... 0


Time: 01:13.42
================= end of McAfee scan log============

Please help how to remove all these trojans/viruses.



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: February 21, 2007 at 15:34:24 Pacific
Reply:

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


0
Reply to Message Icon

Related Posts

See More


shell32.dll - change please help almost a mont...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Generic Downloader.f & many more

generic downloader.ab virus www.computing.net/answers/security/generic-downloaderab-virus/18155.html

Generic Downloader & Almanahe www.computing.net/answers/security/generic-downloader-almanahe/26437.html

downloader.trojan infected my rundl www.computing.net/answers/security/downloadertrojan-infected-my-rundl/11132.html