1. This forum is in read-only mode.

Virus Alert

Discussion in 'Non-Emulation Help' started by klaimore, Nov 26, 2009.

  1. klaimore

    klaimore Well-Known Member

    I downloaded this thinking it was something else, and Avira has been every 10mins Detection Found!
    Detection Found!

    It's mainly located in my temp folder and the folder inside, but when I check all of them, nothings in there.

    Also, it screws up Internet Explorer. IE users don't download.

    Everytime I quarantine it, the same thing pops up over and over again, in a different folder.
    Straight from Virus Information:
    No. Name Type Danger Description Detection added
    1. BDS/Inject.JA Backdoor Server 16 Nov 2009 see here
    2. Worm/VB.aki.2 Worm 16 Nov 2009 see here
    3. TR/Agent.tvb Trojan 16 Nov 2009 see here
    4. TR/Bagle.GE Trojan 16 Nov 2009 see here
    5. BDS/Agent.zwa Backdoor Server 16 Nov 2009 see here
    6. TR/Dldr.Agent.bgyr Trojan 16 Nov 2009 see here
    7. TR/Drop.Agent.ahvf Trojan 16 Nov 2009 see here
    8. TR/Drop.Agent.uws Trojan 16 Nov 2009 see here
    9. TR/Drop.AutoRun.B Trojan 13 Nov 2009 see here
    10. TR/Onlinegames.B.23 Trojan 13 Nov 2009 see here
    11. TR/PSW.Magania.auy Trojan 13 Nov 2009 see here
    12. TR/Onlinegames.B.21 Trojan 13 Nov 2009 see here
    13. Worm/SdBot.446976 Worm 13 Nov 2009 see here
    14. W32/Induc.Gen Malware 03 Nov 2009 see here
    15. TR/ATRAPS.Gen2 Trojan 03 Nov 2009 see here
    16. TR/Click.Yabector.8857.2 Trojan 03 Nov 2009 see here
    17. TR/PSW.Magania.auv Trojan 28 Oct 2009 see here
    18. TR/Dldr.Bredolab.AX Trojan 27 Oct 2009 see here
    19. APPL/Tool.EvID4226 Malware 27 Oct 2009 21 Dec 2006
    20. TR/Drop.Agent.avam Trojan 26 Oct 2009 11 Jul 2009
    21. Worm/Conficker.Autorun.Gen Worm 26 Oct 2009 see here
    22. BDS/Glecia.D Backdoor Server 20 Oct 2009 20 Oct 2009
    23. TR/Vilsel.ior Trojan 20 Oct 2009 20 Oct 2009
    24. TR/PSW.Magania.aul Trojan 19 Oct 2009 27 Feb 2009
    25. TR/PSW.Onlineg.ALZR Trojan 19 Oct 2009 05 Mar 2009
    26. APPL/Tool.EvID4226.A Malware 19 Oct 2009 21 Dec 2006
    27. APPL/KillApplicat.A Malware 19 Oct 2009 12 Mar 2007
    28. Worm/Waledac.48640 Worm 15 Oct 2009 see here
    29. TR/Autorun.142336 Trojan 15 Oct 2009 see here
    30. TR/PCK.Krap.B.151 Trojan 15 Oct 2009 see here
    31. TR/Spy.ZBot.9164.1 Trojan 15 Oct 2009 15 Oct 2009
    32. TR/Vilsel.iop Trojan 15 Oct 2009 15 Oct 2009
    33. APPL/NirCmd.A Malware 14 Oct 2009 28 Jun 2007
    34. APPL/HideDir.A Malware 14 Oct 2009 09 Mar 2007
    35. APPL/KillApp.A Malware 14 Oct 2009 12 Mar 2007
    36. TR/Spy.ZBot.qca Trojan 13 Oct 2009 see here
    37. TR/Dldr.Ebill.L Trojan 13 Oct 2009 see here
    38. TR/Agent.fds.1 Trojan 13 Oct 2009 see here
    39. TR/Spy.ZBot.fql.6 Trojan 12 Oct 2009 see here
    40. TR/Dropper.Gen2 Trojan 12 Oct 2009 see here
     
  2. ace1o1

    ace1o1 Well-Known Member

    why would you give us a link to the virus? ???
     
  3. klaimore

    klaimore Well-Known Member

    It says that it's fully clean, but when you download and run the exe. It disappears. then it's hidden somewhere in your comp.
     
  4. ace1o1

    ace1o1 Well-Known Member

    yep.....sounds like a typical virus!!
     
  5. klaimore

    klaimore Well-Known Member

    Yeah, The file is called KNight Generator exe.
    So I scanned with malwarebytes. Nothing found.
     
  6. Blade5406

    Blade5406 Well-Known Member

    Tried setting your Folder Options so that you'll be able to see hidden files?
     
  7. klaimore

    klaimore Well-Known Member

    How I do that? Thanks.
     
  8. Blade5406

    Blade5406 Well-Known Member

    Read :D
    http://www.bleepingcomputer.com/tutorials/tutorial62.html

    -Some malware, after you download them, change their attribute to Hidden so that you will not be able to see them.
     
  9. klaimore

    klaimore Well-Known Member

    I still can't find it. It keeps moving around in my temp folders. Checked the whole temp 4 times, nothing.
    Is there a antivirus/malware program that can remove this? The file is a trojan. Avira can't do shit.
     
  10. Blade5406

    Blade5406 Well-Known Member

    Oh, shi... it's as if the file you downloaded is an All-in-one package of virus, trojan, etc...
    and I suppose that's a keygen you've downloaded, right?

    I use
    http://www.superantispyware.com/
    and Eset Nod32
     
  11. klaimore

    klaimore Well-Known Member

    Thanks. I'll try that. I'm using free version, so will it detect all of the viruses and kill it?
     
  12. Blade5406

    Blade5406 Well-Known Member

    Yes.

    Might be also be better that if the anti-virus quarantines the file, delete it.
     
  13. theunderling

    theunderling Well-Known Member

    [Avira cant do shit]-Thats crap.Id check the settings,then the USER LOL.

    If the virus gets into your "system volume information" then it will keep coming back until you flush all your system restore points.Run MBAM and SAS to see whats going on first.....
     
  14. Blade5406

    Blade5406 Well-Known Member

    Might be better if you back up any important files and reformat instead.
     
  15. TirithRR

    TirithRR Well-Known Member

    http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
    http://www.safer-networking.org/en/index.html
    http://free.avg.com/us-en/homepage

    With that many viruses, he might lose a lot of important files (they may be infected). Anything on that system is suspect.

    Try and clean it as best as you can. Get rid of all of them. Once it's a livable place you may wish to start fresh.
     
  16. Fennyariel

    Fennyariel Well-Known Member

    Just do what I do! ;v) Backup all the stuff you want to keep then wipe your old hard drive and reinstall Windows! ;v) Like Grandpa always said, "When all else fails, start over!" ;v)
     
  17. TirithRR

    TirithRR Well-Known Member

    But don't do what ever it is that Fennyariel does that makes her have to format and reinstall all the time :)

    (Seriously, you've done that what... 10 times since you've started posting here?) :)
     
  18. theunderling

    theunderling Well-Known Member

    Theres no way Avira let all that through-not if shields are up and databases updated.Hes probably realised Avira would collar the keygen and switched it off
     
  19. klaimore

    klaimore Well-Known Member

    Seriously. It's just the a file called Drop.Ambler.M that keeps popping up now. All the rest dont anymore, so I guess one of the many antivirus I installed/uninstalled killed them.

    Ima try Norton 360
     
  20. theunderling

    theunderling Well-Known Member

    This free AV is rated as the top free one

    http://www.microsoft.com/Security_Essentials/

    Its rated better than even Nod32.

    You need to prevent viruses from accessing your pc