How to remove Trojan Downloader Virus in Win XP?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thehalogod, Oct 22, 2008.

  1. thehalogod

    thehalogod Private E-2

    I've tried several different steps to remove the Trojan Downloader Virus that is in my Windows XP PC. The virus has shown up as multiple different names too i.e. Trojan Downloader ZLOB (I believe was one) but I have seen multiple.

    Are these viruses dangerous enough as to where I should stop working on my computer entirely until this is removed?

    Second - can upgrading to Vista erase some of the infected Windows files?

    In any case this is what I've tried to do to fix it:

    Run AVG Free complete virus scan. After it completes I remove the viruses. I restart my computer and they're still there.

    So I heard somewhere that you have to disable system restore before running the virus scan and restarting the computer because the files hide in there or something (again, I'm not very technical here). In any case, I did this and when I ran the virus scan a couple times nothing cropped up (so I thought it was fixed). But now I just got a little warning from AVG's resident shield that says I have a few different Trojan Downloader viruses.

    If I just copy all of my files from my documents folder and completely wipe the hard drive and start fresh will that fix it as a last resort or will it piggy back onto my external hard drive?

    Lastly, I read through most of the read me first before posting threads but I don't understand half the steps in them.

    Any recommendations? At this point I'm fine with wiping my hard drive as long as I can copy the my documents folder without worry of it coming along.
     
  2. thehalogod

    thehalogod Private E-2

    Edit: (sorry this isn't meant to be a bump I'm just not able to edit my post)

    Update: Here are a few of the other names of the Virus that I've seen it under

    C:\WINDOWS\system32\TDSSriqp.dll
    Trojan horse BHO.FYB

    C:\WINDOWS\system32\TDSSnrsr.dll
    Trojan horse BHO.FXZ
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is not a wise idea because the fact is a dirty restore point is better than none at all. I understand you're having difficulty tackling some of the steps in the Read and Run Me First Procedures...can you tell us what you have done so far and whether you have indeed ran any of the scans? Ask any questions you need to :)

    Thanks
    Kestrel13!
     
  4. thehalogod

    thehalogod Private E-2

    I hadn't tried doing the scans because literally I read through all the readme's and half of the steps were so confusing to me that I didn't even want to try and halfa$$ them and potentially mess them up as well.

    Yes I know this is somewhat ridiculous reasoning but could you just answer these three questions I would really appreciate it:

    If I connect a USB external hard drive to my PC to download files out of my documents folder will the Trojan virus recognize that being installed and install itself on that as well?

    I use Roboform to store all my passwords and have since logged into my email and blog (never had to type the password but everything is there). Is there a chance that these passwords could have been compromised (i.e. as soon as I log in the login info is sent to the virus creator and I get screwed?)

    There isn't anyway to remove this virus by trying a different AV suite right? i.e. Sophos? Once it's in it's in and complicated steps are required to get it out.


    (Basically I'll probably just format my hard drive and upgrade to Vista 64 bit which I had planned to do anyway after SP1 but only based on the answers I see above... I just want to make sure I don't carry anything to the new PC)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since we do not know the extent to which you are really infected without seeing the logs, it is impossible to give you an answer to this. You may or may not be okay.

    Again we cannot properly answer without seeing the logs to know exactly what infections you have.

    Running the READ & RUN ME will most likely remove most if not all of the problems. Anything that remains afterwards would be removed by giving you exact instructions on what to do.

    It's up to you but very little software supports x64 and if these systems get infected, they can be much more difficult to clean due to the fact that specialty tools due not support x64.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds