PDA

View Full Version : nasty little downloader!!



KVLTdotcom
2006-04-21, 15:54
>I am having a great difficulty with what appears to be a "downloader"
>of sorts that i cannot remove or locate with any kind of virus
>software or by a manual search (i've gone through damn near every file
>on my PC). The "downloader" tries to connect to my internet provider
>at random times everyday, crashing any game I may be playing in full
>screen, and giving me the "work offline" or "try again" pop-up box. As
>so far as i know, AVG catches the trojans that the "downloader"
>attempts to install. I receive about 4-6 attempts everyday. I have
>also included a small list of trojans that have appeared due to this
>"downloader"? as well i have included relevent PC specs. Any help
>would be greatly appreciate.
>
> ~~~~trojans~~~
>file name: win1D99.tmp.exe
>path: c:\WINDOWS\temp\
>Discovery: Trojan horse Dialer.BPL
>file size: 13KB
>healable: NO
>
> file name: srvuak[1].exe
>path: c:\Documents and Settings\Administrator.KVLTDOTCOM\Local
>Settings\Temporary Internet Files\Content.IE5\8P8R4RKR\
>Discovery: Trojan horse Dialer.BPL
>file size: 13KB
>healable: NO
>
> File name: win1C38.tmp.exe
>path: C\WINDOWS\temp\
>Discovery: Trojan horse Dialer.BPL
>file size: 13KB
>healable: NO
>
> ~~~PC SPECS~~~
>Processor: Intel Celeron 1.7GHz
>RAM: 1.25 GB RAM
>OS: Windows XP Pro.
>Windows version: 5.1
>Service Pack: Service Pack 2
>Internet Connection: 56K (AOL)

shelf life
2006-04-22, 01:01
hi KVLTdotcom,

boot into SAFE MODE and run your AV or any malware app you have installed.
you reach safe mode by tapping the f8 key during a computer restart, chose first option from list: safe mode.

otherwise see this about posting a HJT log:

http://forums.spybot.info/showthread.php?t=288

tashi
2006-04-27, 00:52
This topic is now closed to prevent others with similar issues posting in it.
If you need it re-opened please send me a pm and provide a link to the thread.