PDA

View Full Version : win32.downloader.gen- Help Please



Snurd
2013-09-04, 18:00
I really hate to bother the forum with this, but I'm at my wit's end! :confused:

I've been trying to remove this virus for several days now with no success. I'm running Windows XP and the virus shows up in SpyBot. It will disappear in safe mode, then reappear in the next regular scan.

I've searched the forum and tried everything that I can understand. I noticed the OTL program and downloaded it. However, I'm afraid to proceed without some guidance.

Here's the latest SpyBot Result. If the entire report if needed, I'll be happy to post it. It's quite lengthy.

Win32.Downloader.gen: [SBI $E6AD2227] Program directory (Directory, nothing done)
C:\Documents and Settings\Keith Simmons\Local Settings\Application Data\Conduit\


Any help is greatly appreciated. Thanks! Keith

tashi
2013-09-04, 19:03
Hello Snurd, :welcome:

Which version of Spybot do you have and did you run with elevated Administrator permissions? Please see this topic in the malware forum: win32.downloader.gen (http://forums.spybot.info/showthread.php?68910-win32-downloader-gen)

Best regards.

Snurd
2013-09-04, 19:07
Hi Tashi,

I'm using version 1.6.0.

I've tried to run in administrator mode, but with XP, a password is required and I haven't been able to get that to work.

Best,

Keith

tashi
2013-09-04, 19:24
Hi Keith,


I've tried to run in administrator mode, but with XP, a password is required and I haven't been able to get that to work.


Are you using an Administrator account on your XP computer? :)

Best regards.

Snurd
2013-09-04, 19:27
When I boot in safe mode, I'm given the choice of "Administrator", or "Keith". If I choose administrator in that mode, no password is prompted, or required.

I've used that administrator account in safe mode, but the virus doesn't appear there in Spybot.

Snurd
2013-09-04, 19:32
Also, In the control panel under user accounts, only "Keith", or "Guest" appear as choices.

tashi
2013-09-04, 19:34
Hi there,

Someone can take a look at the system if you start a topic in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise when available. :)

First see that forum's FAQ which also includes instructions in post #2 on how to provide DDS and aswMBR logs, which are used in the preliminary analysis.

http://forums.spybot.info/showthread.php?t=288

Please include a link back to this thread.

Best regards.

Snurd
2013-09-04, 19:35
Got it. I'll give it a try. Thanks!