downloader-AFH

Thread Solved

Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

downloader-AFH

 
0
  #1
Jan 23rd, 2007
Hey, i have mcafee security centre and when i connect to my internet mcafee detects a trojan called downloader-AFH. I have tried using my virus scan but it doesnt seem to be going away.

Can anyone help me please???
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 538
Reputation: TT4Titans is an unknown quantity at this point 
Solved Threads: 23
TT4Titans's Avatar
TT4Titans TT4Titans is offline Offline
Posting Pro

Re: downloader-AFH

 
0
  #2
Jan 23rd, 2007
Go here and read the characteristics,symptoms and such and it will tell you how to remove.you will need to get into the registry so do exactly as it says.

to see the winstall.exe you may need to go to in my computer - tools - folder options - view and uncheck Hide protected operating system files.

http://vil.nai.com/vil/content/v_136151.htm
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

Re: downloader-AFH

 
0
  #3
Jan 23rd, 2007
Thanks alot that seems to have done the trick
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

Re: downloader-AFH

 
0
  #4
Jan 28th, 2007
It had gone away for a while but its back now and it doesnt seem to be going away as none of the files in that link are actually there, but its still keeps coming up.

HELP!!! please
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 538
Reputation: TT4Titans is an unknown quantity at this point 
Solved Threads: 23
TT4Titans's Avatar
TT4Titans TT4Titans is offline Offline
Posting Pro

Re: downloader-AFH

 
0
  #5
Jan 28th, 2007
Do it again but this time disable your system restore if you do not know how go here.

http://vil.nai.com/vil/SystemHelpDoc...ysRestore.aspx

Also run this free online scan:

http://housecall.trendmicro.com/

After you have done that go here and get HiJackTthis.

http://www.merijn.org/files/hijackthis.zip

run it save log file it will put it where ever you put HJT.I make a folder in my root directory called HiJackThis and put HJT in there.now open the log file copy and paste it in this site.

http://www.hijackthis.de/en

Click analayze it will tell you what to have it fix and what not to fix.

after you are done reboot re-eanble system restore that should take care of it.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

Re: downloader-AFH

 
0
  #6
Jan 28th, 2007
This might seem like a really stupid question. but how do i delete the files that need deleting?
and do i only delete the files with the crosses next to them?
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 16,259
Reputation: jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all 
Solved Threads: 540
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is online now Online
Moderator

Re: downloader-AFH

 
0
  #7
Jan 28th, 2007
the reason the virus might keep coming back is it may be hiding in your system restore area.

boot into safemode (hit f8 repeatedly during windows initial startup)
login as admin
right click on your harddisk and turn system restore off under properties (this wil delete any restore points!)
reboot back into safemode again and turn it back on
start windows normally
If i am helpful, please give me reputation points.
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 538
Reputation: TT4Titans is an unknown quantity at this point 
Solved Threads: 23
TT4Titans's Avatar
TT4Titans TT4Titans is offline Offline
Posting Pro

Re: downloader-AFH

 
0
  #8
Jan 28th, 2007
That's not a stupid question Bud.

No such thing as a Stupid Question just Stupid Answers.LOL

Yes when you paste the log in the analyzer it will have a green check next to good and a yellow next to what has been reported as non threat read the thing next to the marks the red Xs definetley Fix.

The yellow if your not for sure what they are fix anyway.

what you do is with HiJackThis is when you do a scan it has a list of stuff there will be a box next to each one.any box you put a check mark in and at the bottom click fix checked it will fix.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

Re: downloader-AFH

 
0
  #9
Jan 28th, 2007
Not to tempt fate but it looks like its gone for now. Turned my computer on and off a couple of times and it hasnt appeared so thanks for the help. Appreciate it.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 18
Reputation: hazdude is an unknown quantity at this point 
Solved Threads: 0
hazdude hazdude is offline Offline
Newbie Poster

Re: downloader-AFH

 
0
  #10
Jan 28th, 2007
Man alive its come back... i cant believe it. I checked the HijackThis list and found that this (below) was the only red mark that came up. so i can only assume that this is whats causing the problem. Im getting pretty cheesed off, it could be a website that im going on that is getting the trojan on my computer. Any suggestion?O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
http://www.hijackthis.de/gfx/state/nasty.gif
http://www.hijackthis.de/gfx/state/rating_0.gif

The entry &AOL Toolbar search has been identified as nasty.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC