PDA

View Full Version : Problems removing win32.downloader.gen



Twiggler
2013-07-08, 03:50
Hi All

I am having the same issues as others in regards to removing this from Spybot and if someone is able to assist me further that would be appreciated!

Going back to the start, I was getting ads showing up in my browser. I ran spybot and it detected the win32.downloader.gen malware however it couldn't remove it. I did some searching myself for a solution and came across the instructions in this article (http://malwaretips.com/blogs/win32-downloader-gen-trojan/) which I have followed. I am now no longer getting the ads showing up in my browser however spybot is still detecting the malware and is still unable to remove it.

This is the information from the latest spybot report:


--- Report generated: 2013-07-08 11:45 ---

Win32.Downloader.gen: [SBI $F65FFCFA] Library (File, nothing done)
C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll
Properties.size=638560
Properties.md5=6796F6E449F90A543DC3345538ACC46F
Properties.filedate=1308835246
Properties.filedatetext=2011-06-23 23:20:46


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-08-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2013-04-11 Includes\Adware.sbi (*)
2013-07-03 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2013-04-11 Includes\DialerC.sbi (*)
2013-04-11 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2013-04-11 Includes\HijackersC.sbi (*)
2012-11-14 Includes\iPhone.sbi (*)
2013-06-25 Includes\Keyloggers.sbi (*)
2013-04-11 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2013-05-29 Includes\Malware.sbi (*)
2013-06-25 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2013-07-04 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2013-04-11 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2013-05-22 Includes\Spyware.sbi (*)
2013-06-19 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2013-01-16 Includes\Trojans.sbi (*)
2013-06-28 Includes\TrojansC-02.sbi (*)
2013-07-03 Includes\TrojansC-03.sbi (*)
2013-06-27 Includes\TrojansC-04.sbi (*)
2013-06-13 Includes\TrojansC-05.sbi (*)
2013-04-19 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Thanks in advance for the assistance!!!

tashi
2013-07-08, 04:20
Hello Twiggler, :welcome:

Did you run Spybot-S&D as Administrator, as shown in this topic: http://forums.spybot.info/showthread.php?68910-win32-downloader-gen

Please let us know. :)

Twiggler
2013-07-08, 06:14
Hello Twiggler, :welcome:

Did you run Spybot-S&D as Administrator, as shown in this topic: http://forums.spybot.info/showthread.php?68910-win32-downloader-gen

Please let us know. :)

Hi tashi

I didn't see this post in my searching however I ran spybot as administrator and it successfully removed the malware!

Thanks very much for your assistance

tashi
2013-07-08, 06:32
Hi Twiggler,

Hi tashi

I didn't see this post in my searching however I ran spybot as administrator and it successfully removed the malware!

Thanks very much for your assistance
:bigthumb: Glad to help!

iambrianv
2013-10-18, 13:58
Hi Twiggler,

:bigthumb: Glad to help!

don't know how many of my friends computers come to me, with me being the network engineer that peps bring their broken shit to with tears begging the guy who knows about computers to please fix!!!! that i have seen this on.....condiut crap strikes again.....spybot does a good job of removal...although i might have to do an in depth registry search to see if there are any remnant strays in there lurking......but kudos so far to spybot~~~~!!!!!! think before you click yes, to avoid tears later i tell em....to no avail!!!!!

ed2109
2013-11-08, 05:40
I have run spybot (as administrator) 4 times and it's still there in SBI$E6AD227. How do I remove it?

Zenobia
2013-11-08, 19:52
I have run spybot (as administrator) 4 times and it's still there in SBI$E6AD227. How do I remove it?

You could ask for help in malware removal.
Please read the "BEFORE You POST" post:
http://forums.spybot.info/showthread.php?288-quot-BEFORE-You-POST-quot-(Please-read-this-Procedure-Before-Requesting-Assistance)

This is malware removal:
http://forums.spybot.info/forumdisplay.php?22-Malware-Removal

visionblue
2013-12-16, 15:17
I successfully removed it with spybot using administrator services - but should I do anything else to make sure its really gone? Thanks.

Edit: http://forums.spybot.info/showthread.php?69909-After-win32-downloader-gen-removal