Trojandownloader.xs need help removing

Discussion in 'Malware Help (A Specialist Will Reply)' started by raceheads, Mar 27, 2008.

  1. raceheads

    raceheads Private E-2

    My windows security center say's i have a trojandownloader.xs virus.
    My desktop changed to a blue with yellow links and say's that your comp. has several fatal errors due to spyware activity, the links take me to a website that sells spyware.
    here is my hijack log.
    thank you for any help
     

    Attached Files:

    Last edited by a moderator: Mar 27, 2008
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajorGeeks! :major

    I noticed you attempted to start at least 7 threads. They went into moderation because you copy/pasted your hjt log rather than attaching it per the sticky threads at the top of the forum. I have converted your log to an attachment so the thread can be approved.:)

    Also, here is a brief explanation from a previous post of what exaclty Hjt does and does not do.
    I do hope this helps to explain the purpose of HJT.:)




    To get you started on cleaning your system continue with the below.:)


    Note: It is important that you follow the steps exactly as laid out in the guide if you want to effectively and efficiently clean you computer.

    Please follow the steps in our READ AND RUN ME FIRST Malware Removal Guide and then attach the requested logs if you still have a problem. Please be sure to clearly and completely explain the problem you had and any you are still having.

    The following logs should be attached to your next post if you still need assistance.

    C:\ComboFix.txt (Windows 2000, 2003, XP & Vista only)
    SASlog.txt log from SuperAntiSpyware. (all operating systems)
    MGlogs.zip -normally it is C:\MGlogs.zip (all operating systems) - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    Good Luck! :)
     
  3. raceheads

    raceheads Private E-2

    ok i will get busy, sorry about the posts i could not tell if it was working
    thank you very much.
    i will reply when i am done
     
  4. raceheads

    raceheads Private E-2

    I must have messed up some things, i had to uninstall/reinstall my keyboard and mouse in safe mode, finally able to do something.
    i cleaned the registry and unused files with cc cleaner, and did the msconfig thing and then it was trying to reboot and could'nt. still need to defrag and i am working on the list.
    talk soon thanks
     
  5. raceheads

    raceheads Private E-2

    hey no more trojan or pop ups thank you very much for your help. i do have some other issues now, maybe you can help. i cannot access windows firewall it says due to an unidentified problem, windows cannot display windows firewall settings
    and also my printer is gone, if i try to add printer an error box say's
    operation could not be completed. the print spooler service is not running.
    and again thank you very much for you expert help
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should seriously consider posting the logs that were requested in the READ & RUN ME so we can be sure you do not have any other malware.

    NOTE: The Windows firewall is totally inadequate anyway. You need a better firewall. See the ones mentioned in the below.

    How to Protect yourself from malware!


    For your printer problem, did you try starting the Print Spooler Service.
     
  7. raceheads

    raceheads Private E-2

    Ok here are the log files, hope they check out good!
    I know just enough about computers to get in trouble so,
    How do i do the print spooler service?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Print Spooler
    • then right click the entry, select Properties and under Service status: click the Start button to start the service
    • Next please set the Start-up Type to Automatic
    • Click OK until you get back to Windows.
    It's a good thing I said to attach your logs!! The READ ME cleaned up a ton of stuff but we have some more to do.

    You appear to have a broken McAfee SecurityCenter installed. Do you still use McAfee?

    Also you appear to have an incomplete uninstall from having Symantec installed at some time. Please run the below:

    Norton Removal Tool (SymNRT)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software as requested in step 1 of the READ ME:
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
    O2 - BHO: (no name) - {EFC650B7-C53F-4FA6-8AE4-D9B290342F4C} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - (no file)
    O24 - Desktop Component 0: (no name) - C:\Program Files\MSN\vikogiveq.html

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  9. raceheads

    raceheads Private E-2

    Thank you for your help, i will work on the list asap. I must have deleted my spooler service when i was doing the very first cleanup process i do have the logs saved before i changed the registry if that helps or would it i need to buy software? i tried reloading the printer software but it is telling me there is no spooler service. ??
    thanks
     
  10. raceheads

    raceheads Private E-2

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Quote:
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "SpybotDeletingB3024"=-
    "SpybotDeletingD2086"=-

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "TkBellExe"=-
    "QuickTime Task"=-
    "SunJavaUpdateSched"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "SpybotDeletingA6689"=-
    "SpybotDeletingC2089"=-
    "SpybotSnD"=-
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    "PendingFileRenameOperations"=-0
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00





    I saved it and reopened this with notepad, is it supposed to do something,
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC lost the Windows File Association for .REG files. Let's fix it.

    Now Copy the bold text below to notepad. Save it as RegFix.reg to your desktop. Be sure the
    "Save as" type is set to "all files". Then Click Start, Run, and enter regedit and click OK.
    This will open the Registry Editor.

    In the Registry Editor click File and Import. Navigate to the RegFix.reg patch you saved on your
    Desktop and double click on it. Click OK at the prompt to add to the registry. Do you get a success
    message for this?
    Then retry the fixME.reg patch and continue on with the rest of the instructions.
     
  12. raceheads

    raceheads Private E-2

    Here are the logs.
    thanks
     

    Attached Files:

  13. raceheads

    raceheads Private E-2

    I found an older hj log that shows C:\WINDOWS\system32\spoolsv.exe will this help with my printer problem ??
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try doing what I requested in message # 8 to Start the service?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Having the logs is not going to help you unless you have the backups from what you deleted on your own that would be saved in the HijackThis backups folder. Did you delete the spoolsv.exe file along with the service? Check to see if the below file exists:

    C:\WINDOWS\system32\spoolsv.exe

    It looks like you also deleted the below service:
    O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - (no file)

    This is related to AutoPlay functionality such as digital cameras, CD ROM's.

    Why were you doing these things on your own?


    Your logs are clean but it appears that you did not do the below as requested
    What problems are your currently having? For non-malware issues like your services, I will be sending you to the Software Forum.
     
  16. raceheads

    raceheads Private E-2

    Problem solved, I did a destructive restore, It was very easy to do and it appears to have worked fine, thank you for your help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds