I have the downloader-EV virus on my pc and I wonder if anyone knows ow to get it off i am a computer newbie so could you explain in detail
thankyou

Dani AI

Generated

Brief expert note tied to the thread: the symptom describes (only Documents opening) strongly suggests the infection is interfering with normal program launch and/or startup items. First priority is containment — disconnect the PC from the network (unplug Ethernet / turn off Wi‑Fi) and avoid signing into any accounts from that machine. (cisa.gov)

Try to regain a minimal working environment so diagnostic and removal tools can run. On older Windows press F8 at boot to select Safe Mode (or Safe Mode with Networking if necessary), then use Task Manager → File → New Task (Run) to launch msconfig or a command prompt; from there run one‑off scanners or an offline/bootable scan if available. If Windows can’t run installers, prepare the rescue tool on a known‑clean PC and run it from USB/CD on the infected machine. (learn.microsoft.com)

If Safe Mode still blocks tools, create bootable rescue media on a separate clean PC (antivirus rescue ISO) and scan the disk offline; rescue media can also be used to copy personal files safely before doing destructive steps. When copying backups, scan those files on a clean machine before reusing them. If offline cleaning fails or persistence continues, image or back up personal data and plan a clean reinstall. (usa.kaspersky.com)

Quick, practical troubleshooting checklist:

1) Pull network cable / disable Wi‑Fi.
2) Reboot, press F8 → Safe Mode.
3) Ctrl+Alt+Del → Task Manager → File → New Task → run: msconfig
4) From a clean PC: download Microsoft Safety Scanner or Defender Offline to USB, boot/run on infected PC.
5) If all else fails: remove drive, attach to clean PC, copy personal files and scan before restore/reinstall.

Collect diagnostic logs (process list, Event Viewer entries, screenshots) once the system is accessible — that makes community help actionable rather than guessing.

Recommended Answers

All 9 Replies

let me see if i can find some info hold on k

before i search if this is a known problem scan with a virus scan..

Hi there. First up I would go & have an on-line scan from here .
Then download a program called 'HijackThis' & unzip it into it's own folder in My Documents, or somewhere. Not a temporary one or it cannot create backups. Start HJT & scan your computer. DO NOT FIX ANYTHING YET, most of the stuff there is necessary. When the scan is finished the scan button will change to a save button. Save the log to a text file, copy & post it back here.
Get HijackThis here. http://www.zerosrealm.com/downloads/hjt.zip

Too slow again.

no prob crunchie i found what it is though .. its a Trojan horse that takes advantage of a vulnerability in Microsoft Internet Explorer to download and execute arbitrary code on the system.... so a virus scan and removal should take care of this also this definition is is spybot SaD ( look below ) and Adaware 6.0...

when it is executed, it performs the following actions:

  1. Creates the Mutex "BotNetd" so that only one copy of the Trojan runs on the system at any one time.
  2. Attempts to download a file from one of the following servers:

    http:/ /
    http:/ /

    and save the file as one of the following:

    %Windir%\Notepad.exe
    %System%\Notepad.exe
    %Temp%\<random file name>.tmp

    Notes:

    • %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and saves the file to that location.
    • %System% is a variable. The Trojan locates the System folder and saves the file to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
    • %Temp% is a variable. The Trojan locates the temporary folder and saves the file to that location. By default, this is C:\Windows\TEMP (Windows 95/98/Me), or C:\WINNT\Temp (Windows NT/2000), or C:\Document and Settings\<UserName>\Local Settings\Temp (Windows XP).
  3. Adds the value:

    "qbotd"="<filename of Trojan>"

    to the registry key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    so that the Trojan runs when you start Windows

Cool. I'm still learning the ropes at the mo.
Do you know what this is?
O8 - Extra context menu item: &RSDN Search - res://C:\WINDOWS\2020SE~1.DLL/GoRSDN.dll.htm

EDIT Where do you find the definitions in spybot?

Ok this is what I'd like you to do

1.)
Download CWShredder:

Unzip, run and hit the ->next tab to fix all found problems
Reboot.

2.)
Download Spybot - Search & Destroy

pls. read instructions carefully
Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds in Red.
Reboot.


3.)
Download Ad-Aware:
Pls. read the instructions carefully

One final reboot and then post a new HJT log please.

not sure on what it is but it has to do with these tool bars...'My Search Bar' (MySearch variant), 'MyWay Speed Bar' (MyWay) or 'My Web Search Bar' (MyWeb) entries...

i can not open anythng except documents so i can not use any virus scanners or anything but 3 websites have told me i had this virus if any1 wants a picture of what happens leave your email

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.