I have a Dell P4 running XP. I recently picked up a downloader.tooncom virus that is identified as an exploit in Windows Media Player. I have Norton Anti Virus Pro 2004 and Spybot and Pest Patrol, but none of them can remove this virus. Does anyone have any idea how I can get rid of it? It seems to reside in the boot sector somewhere. I have done numerous scans with System Restore OFF, but to no avail.
Thanks in advance for any advice---Aero96

Dani AI

Generated

A short expert addendum tied to the thread: reported a persistent downloader.tooncom infection that ordinary in‑Windows scans did not remove; rightly stressed the importance of current signatures, pointed to vendor guidance, and suggested manual file removals. The pattern in the posts points to a combination of file‑based payloads plus boot‑level persistence, which calls for an offline, repair‑first workflow rather than repeated in‑Windows deletions.

Recommended safe workflow (XP era):

  1. Isolate the machine from networks to stop any active downloaders.

  2. Boot from trusted external media (vendor rescue ISO or a Linux live CD), then back up personal data to external storage and verify those backups later on a known‑clean system.

  3. From the rescue environment, run an up‑to‑date bootable scanner that can inspect the MBR/boot sectors and all volumes; allow quarantine or deletion of confirmed items.

  4. If boot/MBR infection is suspected, boot the original Windows XP CD, enter Recovery Console and run these commands:

    fixmbr
    fixboot
    chkdsk /r

    Run the above only from Recovery Console on a clean CD/USB environment; fixmbr will restore the master boot record safely when used correctly.

  5. After repairs, boot Windows offline, run multiple updated scanners and use autorun/process inspection utilities to check common persistence points. Recreate system restore points only after confirming cleanliness.

Notes and cautions: manual deletion of system files can break Windows — manual removal as suggested in the thread can work but is riskier than offline scanning plus MBR repair. If cleaning fails or confidence is low, export personal data (scan it on another clean machine) and perform a clean OS reinstall. Keep the system fully patched and AV signatures current after recovery.

Recommended Answers

All 5 Replies

*edit* just noticed you tried that alread. :confused:

I have a Dell P4 running XP. I recently picked up a downloader.tooncom virus that is identified as an exploit in Windows Media Player. I have Norton Anti Virus Pro 2004 and Spybot and Pest Patrol, but none of them can remove this virus. Does anyone have any idea how I can get rid of it? It seems to reside in the boot sector somewhere. I have done numerous scans with System Restore OFF, but to no avail.
Thanks in advance for any advice---Aero96

It's actually a Trojan, not a virus, and nearly all current anti-virus software can deal with it, including Norton (as pointed out on the Symantec site via Google), as well as the free version of Grisoft AVG. Make sure that your virus definition files are up-to-date, as it's only about a month old.

Thanks much for the referral. Unfortunately, I have done everything suggested on the Symantec web site but it hasn't cleared the problem yet. Occassionally, I also get a "runtime" error, with a message asking if I want to debug. Do you have any idea what this means? Thanks

2 aero
there is only one way to completely get rid of this troyan - run your computer in safe mode, after removing iedll.exe by your antivirus you have to remove loader.exe from windows folder and from prefetch folder manually. enjoy:)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.