Update: Ad-Aware shows that it hasn't been updated in 118 days.

Malicious websites, or legitimate websites that have been compromised, may drop this trojan onto a compromised computer. Summary : Trojan.Downloader-Gen/Inst2.Process Description : Trojan.Downloader-Gen/Inst2 installs and downloads various malware packages.Trojans are programs that can appear to serve a legitimate purpose but actually have an unwanted or harmful Note the rootkit in this log, as AVG, McAfee, and Norton completely miss it, yet SAS, BitDefender, Nod32, Kaspersky, and a few other better quality apps will find it.

The customer followed up with a full scan) SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 05/23/2007 at 02:31 PM Application Version : 3.7.1018 Core Rules Database Version : 3243 Trace Rules Database Version:

scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\ControlSet001\Services\ati2mtag] [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\ATI2MTAG] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ati2mtag] "ImagePath"="System32\DRIVERS\ati2mtag.sys" [HKEY_LOCAL_MACHINE\system\ControlSet002\Hardware Profiles\0001\System\ControlSet001\Services\ati2mtag] [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\ControlSet001\Services\ati2mtag] [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\ATI2MTAG] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ati2mtag] "ImagePath"="System32\DRIVERS\ati2mtag.sys" [HKEY_LOCAL_MACHINE\system\ControlSet002\Hardware Profiles\0001\System\ControlSet001\Services\ati2mtag] [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\VGASAVE] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\VgaSave] "ImagePath"="\SystemRoot\System32\drivers\vga.sys" [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\ControlSet001\Services\ati2mtag] [HKEY_LOCAL_MACHINE\system\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\ATI2MTAG] STEP 2: Remove Win32.downloader.gen malicious files with Malwarebytes Anti-Malware Malwarebytes Chameleon technologies will allow us to install and run a Malwarebytes Anti-Malware scan without being blocked by Win32.downloader.gen. In the new open window,we will need to enable Detect TDLFS file system, then click on OK. help for clueless Started by bdstrange , Jun 06 2007 04:58 PM Please log in to reply 14 replies to this topic #1 bdstrange bdstrange New Member Members 8 posts Posted

Once it has done this, it will update Malwarebytes Anti-Malware, and you'll need to click OK when it says that the database was updated successfully.

No wonder HijackThis would not even run... Reply With Quote August 24th, 2009,08:23 PM #15 Broni View Profile View Forum Posts Visit Homepage Malware Annihilator Join Date Dec 2007 Location Daly City, CA Posts 22,131 Making sure, your Reply With Quote August 24th, 2009,07:37 PM #13 Broni View Profile View Forum Posts Visit Homepage Malware Annihilator Join Date Dec 2007 Location Daly City, CA Posts 22,131 Malwarebytes log says Otherwise...

Process C:\RECYCLER\S-1-5-21-1659004503-1425521274-839522115-500\DC123.EXE C:\RECYCLER\S-1-5-21-1659004503-1425521274-839522115-500\DC256.EXETrojan.Downloader-UDL2 C:\WINDOWS\FPMD8L20.EXETrojan.Smitfraud Variant C:\WINDOWS\SYSTEM32\GWQUVW.DLLTrojan.Downloader-IPV6Mons C:\WINDOWS\SYSTEM32\IPV6MONS.DLL This customer is selling the computer and wants it wiped. From normal mode I've managed to at least get the desktop to change back to the previous background, but in the desktop tab all the background are unselectable.

The SAS scan is about half way through and has picked up about a dozen forms of malware. Malware - short for malicious software - is an umbrella term that refers to any software program deliberately created to perform an unauthorized and often harmful action. i have run ad-aware and does not help. In this support forum, a trained staff member will help you clean-up your device by using advanced tools.

Its removal is recommended.

KASPERSKY TDSSKILLER DOWNLOAD LINK(This link will automatically download Kaspersky TDSSKiller on your computer.) Before you can run Kaspersky TDSSKiller, you first need to rename it so that you can get it to run.

I have had no luck in removing them.

After the Emsisoft Emergency Kit has update has completed,click on the Menu tab,then select Scan PC.

Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.