How do I remove Downloader virus??? Help!

How do I remove Downloader virus??? Help!

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How do I remove Downloader virus??? Help! BrianNo 07-13-2006
Posted by on July 13, 2006, 9:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My Norton AntiVirus Software detected a "Downloader" virus at
"C:\WINDOWS\system32\autlog.dll". The Software can't fix, quarantine,
or delete the infected file, even though all the definitions have been
updated. I've gone on SafeMode and tried to scan and remove the virus
from there, but it still won't. I've also tried to manually remove it
by going to the location and trying to delete the file in question, but
the computer won't let me. I've run AdAware as well but Norton
AntiVirus is still saying I have it, and the pop-up warning window
won't go away!

Someone told me that I can't remove it manually because the infected
file is a registry file. So the question is, how do I remove this thing
from my computer? Please help! Thanks!


Posted by Malke on July 13, 2006, 10:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
BrianNo@gmail.com wrote:

> My Norton AntiVirus Software detected a "Downloader" virus at
> "C:\WINDOWS\system32\autlog.dll". The Software can't fix, quarantine,
> or delete the infected file, even though all the definitions have been
> updated. I've gone on SafeMode and tried to scan and remove the virus
> from there, but it still won't. I've also tried to manually remove it
> by going to the location and trying to delete the file in question, but
> the computer won't let me. I've run AdAware as well but Norton
> AntiVirus is still saying I have it, and the pop-up warning window
> won't go away!
>
> Someone told me that I can't remove it manually because the infected
> file is a registry file. So the question is, how do I remove this thing
> from my computer? Please help! Thanks!

A "Downloader" virus is too generic a term. Didn't NAV give you an actual
name? If it did, what is it? Googling for "autlog.dll" brought me nothing
which isn't unusual for malware, since it is common for viruses and malware
to have random names.

You can try scanning with David Lipman's Multi_AV or Sysclean:

http://www.elephantboycomputers.com/page2.html#TrendMicros_Sysclean
http://www.ik-cs.com/multi-av.htm - how to use Dave Lipman's Multi-AV
http://www.ik-cs.com/programs/virtools/Multi_AV.exe - Multi-AV download
http://pcdid.com/Multi_AV.htm - additional Multi_AV instructions

You might also want to scan with Ewido and go through some of the other
removal steps here:
http://www.elephantboycomputers.com/page2.html#Removing_Malware

If none of that works, you should run HijackThis and post your log at one of
the specialty forums listed at the site above (not here, please).

Otherwise, take the machine to a professional computer repair shop (not your
local version of BigStoreUSA).

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by on July 14, 2006, 6:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi. I tried your Sysclean software, and I followed the directions, but
the software didn't find any infections on my computer. When I
restarted my computer on normal mode, NAV said that I still have the
"Downloader" virus.

Also, that's the only name NAV will give me. All it says is that it's a
Trojan Horse virus and that it's called "Downloader".

Perhaps there's another way to remove this virus before it wreaks havoc
on my computer?

Thanks.


Posted by Malke on July 14, 2006, 8:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
BrianNo@gmail.com wrote:

> Hi. I tried your Sysclean software, and I followed the directions, but
> the software didn't find any infections on my computer. When I
> restarted my computer on normal mode, NAV said that I still have the
> "Downloader" virus.
>
> Also, that's the only name NAV will give me. All it says is that it's a
> Trojan Horse virus and that it's called "Downloader".
>
> Perhaps there's another way to remove this virus before it wreaks havoc
> on my computer?

What happens when you try to delete the autlog.dll file? If you get an error
message, what does it say? Are you using a current version of NAV (2005/06)
with updated virus definitions?

Things to try:

1. Right-click on the file and look on the Version tab if it exists. This
can help get information about where the file came from, although most
malware doesn't have it.

2. If I were working on the machine and was *very* sure the file was malware
(and since I'm not and can't see your computer please take this advice with
that caveat):

a. If the file is in use and can't be deleted or renamed in Safe Mode, I
would try Safe Mode Command Prompt. Navigate to the file location and try
deleting it from the command line.

b. If that didn't work, I would boot the system outside of Windows with
either a Bart's PE or other professional tool and delete the file that way.
You may or may not have the ability to do this; there is no way for me to
know.

3. Have you run Ewido as I suggested? I would. Make sure you update it and
then boot into Safe Mode to scan.

4. If Ewido doesn't find anything, do as I also suggested and run HijackThis
and post your log to one of the following specialty forums (not here,
please):

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
http://aumha.net/viewforum.php?f=30
http://castlecops.com/forum67.html
http://spywarewarrior.com/viewforum.php?f=5
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

5. Send the autlog.dll to VirusTotal to see if they can identify it.
http://www.virustotal.com/flash/index_en.html

6. Take the machine to a professional computer repair shop (not a big box
store) where someone skilled in virus/malware removal can look at it.

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by Vladimir Scherbina on July 14, 2006, 11:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Malke, I guess simply deleting file would not help because as OP wrote AV's
tried to do that without success.

To OP: most likely this dll module is injected into system processes, I
would use Far (http://farmanager.com/) to search where this module is
loaded - goto processes tab, alt + f7 and search for occurences of 'autlog'
string. If it will be found in processes let us know where exactly. Another
option is to search for this dll in registry. It can be registered as BHO or
Winlogon notification package. Removing usually helps - but only for cases
when module does not protect itself.

--
Vladimir (Windows SDK MVP)

> BrianNo@gmail.com wrote:
>
>> Hi. I tried your Sysclean software, and I followed the directions, but
>> the software didn't find any infections on my computer. When I
>> restarted my computer on normal mode, NAV said that I still have the
>> "Downloader" virus.
>>
>> Also, that's the only name NAV will give me. All it says is that it's a
>> Trojan Horse virus and that it's called "Downloader".
>>
>> Perhaps there's another way to remove this virus before it wreaks havoc
>> on my computer?
>
> What happens when you try to delete the autlog.dll file? If you get an
> error
> message, what does it say? Are you using a current version of NAV
> (2005/06)
> with updated virus definitions?
>
> Things to try:
>
> 1. Right-click on the file and look on the Version tab if it exists. This
> can help get information about where the file came from, although most
> malware doesn't have it.
>
> 2. If I were working on the machine and was *very* sure the file was
> malware
> (and since I'm not and can't see your computer please take this advice
> with
> that caveat):
>
> a. If the file is in use and can't be deleted or renamed in Safe Mode, I
> would try Safe Mode Command Prompt. Navigate to the file location and try
> deleting it from the command line.
>
> b. If that didn't work, I would boot the system outside of Windows with
> either a Bart's PE or other professional tool and delete the file that
> way.
> You may or may not have the ability to do this; there is no way for me to
> know.
>
> 3. Have you run Ewido as I suggested? I would. Make sure you update it and
> then boot into Safe Mode to scan.
>
> 4. If Ewido doesn't find anything, do as I also suggested and run
> HijackThis
> and post your log to one of the following specialty forums (not here,
> please):
>
> http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
> http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
> http://aumha.net/viewforum.php?f=30
> http://castlecops.com/forum67.html
> http://spywarewarrior.com/viewforum.php?f=5
> http://www.wilderssecurity.com/
> http://forums.tomcoyote.org/
>
> 5. Send the autlog.dll to VirusTotal to see if they can identify it.
> http://www.virustotal.com/flash/index_en.html
>
> 6. Take the machine to a professional computer repair shop (not a big box
> store) where someone skilled in virus/malware removal can look at it.
>
> Malke
> --
> MS-MVP Windows Shell/User
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic"


Similar ThreadsPosted
avg found a virus called downloader.tibs October 4, 2006, 5:06 pm
JS Downloader Agent (Virus) and Trojan Horses January 27, 2008, 2:24 pm
How do I remove Purstiu Virus July 15, 2005, 3:51 pm
how to remove "service manager" virus? May 11, 2006, 10:30 pm
avmete.dll - Virus file - cannot remove December 21, 2007, 12:46 pm
Downloader AQ December 7, 2006, 11:40 am
Downloader.Zlob.YQ May 7, 2006, 6:19 am
Downloader-Awx Trojan June 20, 2006, 5:00 pm
High downloader October 12, 2007, 6:11 pm
Trojon Downloader Will not delte help April 13, 2006, 9:40 am

The site map in XML format XML site map

Contact Us | Privacy Policy