This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

downloader.ab virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, here is what I got from Kasperskey…… Kaspersky File Scanner Attention! Kaspersky Anti-Virus has detected a virus in the file you have submitted. We suggest that you consider: * Reading about the virus/viruses in our Virus Encyclopedia * Downloading a trial version of Kaspersky Anti-Virus * Purchasing a copy of Kaspersky Anti-Virus in our E-Store * Purchasing Kaspersky Anti-Virus from a certified partner Scanned file: system32:jjaa.dll system32:jjaa.dll - infected by Trojan-Downloader.Win32.Small.azk I guess the name of the Trojan is 'Trojan-Downloader.Win32.small.azk', which is what Ewido defined it as……but there doesnt seem to be detailed information on this trojan, or how to get rid of it….
Go here and run at least one of the online scans, allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done.

Next:

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
This thing will not go away……Ive scanned with just about everything over and over, and according only to Ewido it is still there……..The following is a step by step of my latest attempt……

(all programs are up to date)

1. Ran TrendMicro Housecall…………….found Nothing

2. Ran eTrust Antivirus web scan……….found Nothing

3. Ran Panda Activescan………………….found Nothing

4. Ran Spybot……………..found some spyware items and cleaned them

5. Ran AdAware…………………….found Nothing

6. Ran CWShredder…………………found Nothing

7. Ran Ewido……………….found the trojan, plus other items (see log below)

8. Ran Regedit, searched for jjaa…………found Nothing

9. Deleted Recycle Bin, Turned off System restore, then rebooted.

10. Once I rebooted, I reran Ewido………found the trojan Again! (as a test, I didnt remove the trojan, and again searched Regedit for jjaa…..but did not find anything this time, but for all I know I can search the registry again in 20 mins and Ill get those two entries that Ive found before (see prior posts)

***NOTE***
What ever this thing is, and whatever it does…….all I can say is that it doesnt appear to be affecting my system performance, its just very worrisome that something is on my PC and I dont know what its doing. Its in my opinion that this trojan exploits Internet Explorer, and downloads adware/spyware when you use IE. I no longer use IE for that very reason, I use Firefox….but I came to that hypothesis because Spybot found a bunch of junk it never had before, only after I used the three online virus scans you recommended, which I had to run through Internet Explorer.

What is your opinion?
Does my Hijackthis log look clean?
What else can I do?
Your help is greatly appreciated!


Logfile of HijackThis v1.99.1
Scan saved at 7:16:29 PM, on 9/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\devldr32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Smalls\Desktop\Fix\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - file://D:\GAMES\msjavx86_3805.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15008/CTPID.cab
O16 - DPF: {F992FDC0-DAA7-4774-B01C-E9DFF19FE0FE} (Invoke Solutions MILive Participant Control(MR)) - http://online.invokesolutions.com/events/b…7203/MILive.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - file://D:\GAMES\WebDriverFullInstall.exe
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 11:36:59 PM, 9/26/2005
+ Report-Checksum: BC28E36D

+ Scan result:

:mozilla.6:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.7:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.8:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.9:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.28:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.29:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.51:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned without backup
:mozilla.60:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned without backup
:mozilla.61:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned without backup
:mozilla.62:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.63:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.64:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
:mozilla.65:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
:mozilla.66:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
C:\WINDOWS\system32:jjaa.dll -> TrojanDownloader.Small.azk : Cleaned without backup


::Report End
I would like to make sure we get that file killed. It shows as a virus and it could re-infect you at any time. We have a few other things to try.

Download this program.

http://downloads.subratam.org/DllCompare.exe

Open the program and click the "Run Locate.com" button.
Then click the "Compare" button (this will take a few minutes)
When it finishes click the "Make Log…." button.

Post the dll compare log to this thread.
* DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 1,263 items found: 1,263 files, 0 directories. Total of file sizes: 260,930,803 bytes 248.84 M Administrator Account = True ——————–End log———————
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Start Killbox, Use standard file kill.(default settings).
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINDOWS\system32:jjaa.dll


Back in Killbox go > file > paste from clipboard, now click the red X
that looks like a stop sign, wait until a success message appears.
Repeat those same step's until each file has been deleted.


Note: if a file cannot be deleted [x] check delete on reboot, then go back to
standard file kill for the next file in the list.

When finished exit Killbox and restart your PC.
:( Killbox was unable to delete the file directly….. So I checked to delete on reboot, Killbox then asked if I wish to reboot, I clicked yes, then it displayed a message…something about searching the registry……then I got an error message……………. 'PendingFileRenameOperations Registry Data has been removed by External process'
No! its still here I forgot to add on my last post………….i then clicked ok on that 'error' message, all of my desktop icons had dissapeared, including the start menu/task bar…..so i cntl-alt-delete to reboot………..after reboot, I went back into killbox……typed in the path/file name……and clicked on show file propeties…..and it found the file again
Start Killbox place a tick next to [x]Replace on reboot and >[x]Use Dummy.
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINDOWS\system32:jjaa.dll


Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Ok, I went through the process…….. just to check that I did it right….. I entered C:\WINDOWS\system32:jjaa.dll in the 'file to be deleted', and I left the automatic entry C:\Documents and Settings\Smalls\Local Settings\Temp\kbdummy.6 as is when i selected Use Dummy….. I then rebooted….. but I believe the C:\WINDOWS\system32:jjaa.dll is still here
Turn off System Restore: On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. Restart your computer, turn it back on. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Remove the Check Turn off System Restore. Click Apply, and then click OK. Search for :jjaa.dll and see if it's there. If it's still there, restart in Safe Mode and try killbox.
this sucker will just not go away……. the file was still there after first killbox run, then i went into safe mode and tried the standard kill……was unable to delete, and I tried delete on reboot…..i got that same 'PendingFileRenameOperations Registry Data has been removed by External process' message, and I tried replace file with dummy on reboot, and it still didnt work

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI