View Single Post
Old 05-28-09, 09:55 PM   #1
Jerry_03
Registered User
 
Jerry_03's Avatar
 
Join Date: Dec 2007
Posts: 17
Default Need help removing virus (Downloader.Generic8.APEH)

Sorry if this isnt the correct forum to post this in but in any case:

I'm Trying to help my brother remove a virus from his computer. He got it by downloading a program that ended up containing a trojan horse virus. He is using Windows XP Home Ed.

Symptoms of the virus includes not being able to access some AV sites. Mostly the free ones like AVG, Avast and NOD32 (i can however access the ones that arnt free like Norton and McAfee). As a result i cant update the definitions on AVG free. also theres some "pop-ups". its attempting to use IE (My brother uses Firefox) to show pop-ups but these errors are being shown instead:



When the IE popup script errors came on screen i checked task manager and the following processes was the virus running in the background:

msb.exe and 17067.exe

by ending it in task manager the popup script errors went away but they would return every 30 minutes or so. also the 17067.exe process tookup a lot of memory usage, around 200,000 K.

I ran a AVG scan and found out the name of the virus is Trojan horse Downloader.Generic8.APEH. I typed the name of the virus in google to find some solutions to removing it and couldn't really find anything useful.

I used AVG to move it virus vault and delete it but apparently it didnt work cause its still having the symptoms like not being able to access the AV sites and the popup scripts errors.

However AVG did show the location of where the virus had been installed to and i went to that directory:

C:\Documents and Settings\Username\Local Settings\Temp

i found these files here and deleted it:



Im still getting the virus symptoms but when the pop-up script occurs there is no 17067.exe in the task manager, just the msb.exe. as before ending it closes the popup script error box but it shows up again every 30 mins.

if anyone knows of a solution or program that i can use to remove the virus then it would be greatly appreciated. Thanks in advance.
__________________
CM Centurion 5 | Intel Core 2 Duo E6750 @ Stock 2.66ghz (Stock HSF) | NVIDIA GTX 260 896MB (192) @ Stock 575/2000 (Stock HSF) | OCZ SLI-Ready 2gb DDR2 800mhz @ Stock 4-4-4-15 1T timings | Creative SB Audigy 2 | Samsung Spinpoint F1 750gb 7200RPM SATA; Seagate 320gb 7200RPM SATA; WD Raptor 150gb 10000RPM SATA |WinXP Home 32-bit
Jerry_03 is offline   Reply With Quote