PDA

View Full Version : Generic Multidropper d and others



Modzilla
2006-10-20, 16:54
OK, got infected through MSN Messanger, and so did everyone else in my address book and everyone in their address books and so on.

So far ive found the following malware:

Trojan Generic Mutidropper d
Trojan new malware j
Trojan Agent HBZ
Media Tickets
Dallar revanue
Known Bad Sites
Service 9 x
maxifiles
i.e. security settings.

On my descktop the following icons have appeared:

drsmartload
WEN
ONE
TWO

I have McAfee security centre and every 5 mins or so it pops up "detected generictrojandropper d, i delete it, it says it can be deleted, so i cancel, and then it says it deleted it, but 5 mins later up it pops again!

Ive run the following:

sptbot
adaware pro
spydoctor (free version without removal)
Trend micro housecall
Pandascan free online scanner.

I have no idea what malware is left but i think most of it is.

I cannot remove the desk top icons (which im sure are malicious) though my own knowledge level.

Please help me and i'll give my friends the link to fix their putors too!

Oh, and i still get the firehousezone cookie in my firefox browser daily (previous thread with no up to date reply).

Thanks team!

tashi
2006-10-20, 17:03
Hi Modzilla :greeting:

I see you have a few posts in the past couple of days and the computer was recently cleaned up here:
http://forums.spybot.info/showthread.php?t=7479

Let's see a log. ;)

Please run the Spybot-S&D and on-line anti virus scans (separately) as shown here:

"BEFORE you POST" -Preliminary Steps and scanning with SPYBOT-S&D (http://forums.spybot.info/showthread.php?t=288)

Then start your own thread in the malware forum:

Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22)

Once you have posted, a helper will take a look at the logs as soon as available and give any further instructions necessary.

Cheers.

Modzilla
2006-10-23, 04:23
Done here: http://forums.spybot.info/showthread.php?p=48136#post48136

SpySentinel
2006-10-25, 03:15
Also if you can submit the files to detections@spybot.info