This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

downloader.ab virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let's try this:

Click Start> Run> type in CMD tap enter

at the Command Prompt type in: Attrib -R -H -S C:\WINDOWS\system32:jjaa.dll tap enter

Then try: Ren C:\WINDOWS\system32:jjaa.dll C:\WINDOWS\system32:jjaa.old tap enter.

Then try: Del C:\WINDOWS\system32:jjaa.old tap enter

Type exit.

Now see if it's gone.
the command prompt was unable to find the file…after typing Attrib…..it said File not found……. it seems to be that only Ewido, and killbox is able to find (see) the file….. **note** when I click on show file properties when Im in killbox this is what is displayed…. Type of File: File Folder Opens with: Unknown application Location: C:\Windows\system32: Size: 0 bytes Size on disk: 0 bytes Created: (blank) ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 8:32:41 PM, 9/28/2005 + Report-Checksum: EF121AA5 + Scan result: C:\WINDOWS\system32:jjaa.dll -> TrojanDownloader.Small.azk : Ignored :mozilla.8:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup :mozilla.9:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.10:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.11:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.12:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.13:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.14:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.15:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.16:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.17:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.18:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.19:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.21:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup ::Report End
No i dont, thats the most puzzling thing……….. I thought that : wasnt even a valid character to name either a file or a folder? I cant find C:\Windows\system32:jjaa.dll in either windows explorer, command prompt, or windows search (and I do have display all hidden files and folders activated in my windows settings) I just reran Ewido, and this time had it remove the file……as a test I went into killbox, entered in the path/file and clicked show properties…….and the properties window came up………does this mean Ewido is really not removing it?…..I am now currently rerunning Ewido, to see if it will find the file again………(this has all been done without a reboot)
I uploaded xphidden.reg into the registry…….and it didnt reveal anything new……… LDTate Posted Yesterday, 09:41 PM After Reboot was iy still there? Yes, it is still there after reboot……. Im very suspicious about Ewido, it does not seem to be able to "clean"/delete files like its supposed to……..if you look at the last log I posted of an Ewido scan it lists several spyware cookies as well as the trojan, I had selected to remove those without backup, but yet, after rebooting and scanning with Ewido, it found them again…… Not very happy about that……. I was able to get rid of those cookies using CCleaner. I have sent an email to Ewido, and Kaspersky (the only two programs that seem to be able to recognize the file on my system) to see if they can provide more information about system32:jjaa.dll…….but god only knows when and if Ill get a response. Do you have any further suggestions?
Does jjaa.dll show in the registry? I beginning to think it's a ghost. Look for a folder called C:\!submit. If found, delete it. It's from Ewido and contains the cleaned files. Ewido will re-create the folder next time it's run.
I found the C:\!submit folder and deleted it….. On my last several attempts to search the registry for "jjaa" I have be unable to find anything….. If memory serves me correct, I believe I found two entries in the registry only two times…….(and was only able to delete one)……..but like I said I havent found anything in my last several searches. What do you mean by "ghost" exactly? P.S. I did actually get a reply from Ewido support, and ive submitted my scan log, and hijackthis log to them….so i am waiting to hear back from them
BRAVO!!! MY FRIEND!! BRAVO!!!! :D I never even explored all through hijackthis before (probably should have), but I ran ADS scan and it not only found it, but it has appeared to actually delete it! Finally a program that can see the file, and then actually delete it…….. Well I rebooted and reran the ADS scan, and it didnt find it, then I ran killbox to show file properties for C:\Windows\system32:jjaa.dll and it was unable to find it…..I still want to rerun Ewido to check, but unfortunately dont have time right now……. Someone did contact me from Ewido, but its now been a couple days since I first heard from them…….. so, out of curiousity, do you have any knowledge about 'Alternate data streams'? what do they do? What in my system was at risk? Im assuming (as was stated in hijackthis) that ADS is becoming more used by trojans and viruses….we'll have to start spreading the word, to hopefully help others out and save them time when they run into a problem such as I did. :thumbup: I will do a reboot and full scan again tomorrow just to be totally sure. Many thank yous for you time and help!!! it is very appreciated! - Anthony
P.S. the ADS scan also displayed this file…… c:\windows\mhqud.dat : rhyswu but im not sure if it is a valid file or not……..should I delete it?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI