This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help removing tr\crypt.xdr.gen trojan!

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! I have a trojan called tr\crypt.xdr.gen. I have scanned with mcafee, ad-aware, avira anti-virus, and advanced system care, yet none of them have removed the virus entirely. I get a notification from my avira saying it has blocked the "tr\crypt.xdr.gen" trojan. sometimes every 5-15 minutes, sometimes i wont get it for over an hour. Here is my hijack this log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 8:46:24 PM, on 6/30/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16827) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\program files\steam\steam.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\System32\dllhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Java\jre6\bin\java.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\System32\msiexec.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe – End of file - 2139 bytes ————— ive also seen a few forum posts on here about the same virus saying to scan with the kaspersky online scanner and include that log also, so i went ahead and did that. Here is my kaspersky online scanner log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, June 30, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, June 30, 2010 22:55:04 Records in database: 4263627 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 65602 Threats found: 7 Infected objects found: 8 Suspicious objects found: 0 Scan duration: 01:33:09 File name / Threat / Threats count C:\Documents and Settings\Joey Harter\Local Settings\Temp\bxwn.exe Infected: Trojan-Downloader.Win32.Mufanom.vjo 1 C:\Documents and Settings\Joey Harter\Local Settings\Temp\qodigx.exe Infected: Packed.Win32.Krap.ao 1 C:\Program Files\ESEA\ESEA Client\eseaclient.css.dll Infected: Backdoor.Win32.Turkojan.hvn 1 C:\Program Files\ESEA\ESEA Client\eseaclient.tf2.dll Infected: Backdoor.Win32.Turkojan.hvm 1 C:\Program Files\NN MiRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1 C:\Program Files\Trend Micro\HijackThis\backups\backup-20100629-181402-197.dll Infected: Trojan.Win32.BHO.ahuh 1 C:\WINDOWS\dinwmql.dll Infected: Trojan-Downloader.Win32.Mufanom.vjn 1 C:\WINDOWS\system32\tjxrt.dll Infected: Trojan.Win32.BHO.ahuh 1 Selected area has been scanned. ———————— I am tempted to go ahead and delete all of these files that are infected manually since kaspersky has given me the direct file path, but i will just wait to hear from someone on here to tell me what to do. thank you VERY MUCH in advance and i hope to be able to fix my computer without having to reformat.
Hello esnev and welcome to the forums here at WhattheTech.

:welcome:

I can give you a script using one of our tools to delete those files if you haven't already done so. Let me know, then:

Please follow the instructions at this link. Then post the logs from DDS back to this link. Do not start a new topic.
Hello IndiGenus!! thanks so much for replying. no, i havnt deleted any of those files, so i would like it if you gave me a tool to help do that. when i'm done doing that, i'll take the next step by following the instructions on that other page you linke me to
Do you use or know of the ESEA program on your computer? Looks like some kind of anti-cheat engine? Kaspersky flagged files from that along with the mIrc which is a false positive. I'll leave those for now.

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\Documents and Settings\Joey Harter\Local Settings\Temp\bxwn.exe 
    C:\Documents and Settings\Joey Harter\Local Settings\Temp\qodigx.exe
    C:\WINDOWS\dinwmql.dll
    C:\WINDOWS\system32\tjxrt.dll
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
yes, i do use the esea program from time to time and yes it is a counter-strike anti-cheat program. but if there is a trojan being detected in there, i have no problem removing that program since i dont use it enough anyways. Here is my old timer log: All processes killed ========== PROCESSES ========== Process explorer.exe killed successfully! ========== FILES ========== C:\Documents and Settings\Joey Harter\Local Settings\Temp\bxwn.exe moved successfully. C:\Documents and Settings\Joey Harter\Local Settings\Temp\qodigx.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\dinwmql.dll C:\WINDOWS\dinwmql.dll moved successfully. C:\WINDOWS\system32\tjxrt.dll moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Joey Harter ->Temp folder emptied: 109929853 bytes ->Temporary Internet Files folder emptied: 22072836 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 856432 bytes ->Flash cache emptied: 1072 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 80413 bytes ->Flash cache emptied: 596 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 18585377 bytes ->Flash cache emptied: 10462 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1138618 bytes %systemroot%\System32 .tmp files removed: 2891281 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 361630 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34105 bytes RecycleBin emptied: 20171538 bytes Total Files Cleaned = 168.00 mb OTM by OldTimer - Version 3.1.12.2 log created on 07012010_115724 So, whats next sir?

yes, i do use the esea program from time to time and yes it is a counter-strike anti-cheat program. but if there is a trojan being detected in there, i have no problem removing that program since i dont use it enough anyways.

No, it's a false positive by Kaspersky. Just by the nature of the program it has behavior like Malware. Same with mIrc. They can be left.

Please follow the instructions at the link I gave earlier and post the DDS logs. Let me know how it's running now too please.
Here is the DDS logs: DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 12:07:41.12 on Thu 07/01/2010 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1568 [GMT -7:00] AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\program files\steam\steam.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Joey Harter\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Steam] "c:\program files\steam\steam.exe" -silent mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-14 64288] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-6-30 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-6-30 135336] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-6-30 267432] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-6-30 60936] S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-8-9 12672] S4 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2001-8-18 14336] S4 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?] S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1181328] =============== Created Last 30 ================ 2010-07-01 18:57:24 0 d—–w- C:\_OTM 2010-06-30 20:51:14 0 d—–w- c:\windows\system32\NtmsData 2010-06-30 20:16:45 0 d—–w- c:\docume~1\joeyha~1\applic~1\IObit 2010-06-30 20:16:44 0 d—–w- c:\program files\Advanced SystemCare 3 2010-06-30 19:03:12 0 d—–w- c:\docume~1\joeyha~1\applic~1\Avira 2010-06-30 18:53:31 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2010-06-30 18:53:30 0 d—–w- c:\program files\Avira 2010-06-30 18:53:30 0 d—–w- c:\docume~1\alluse~1\applic~1\Avira 2010-06-30 02:59:31 664 —-a-w- c:\windows\system32\d3d9caps.dat 2010-06-30 01:11:47 0 d—–w- c:\docume~1\joeyha~1\applic~1\Street-Ads 2010-06-30 01:10:46 62464 –sha-r- c:\windows\system32\WgaTrayf.dll 2010-06-30 01:10:44 0 d—–w- c:\docume~1\joeyha~1\applic~1\F360F1032306F3B1CD946FEABF7C9599 ==================== Find3M ==================== 2009-12-16 20:06:51 89184 —-a-w- c:\program files\PhotoFunia-436065e.jpg 2008-08-23 22:48:20 596480 —-a-w- c:\program files\cal_acs.exe ============= FINISH: 12:08:32.57 =============== its running smooth, the avira hasnt given me a stupid notification saying the tr\crypt.xdr.gen virus has been found lol.
Okay great, glad it's running better.

Another good free scanning program is MalwareBytes. I would suggest you download, update it, and run a scan.

First,
Use ATF Cleaner to remove temp files, cookies, cache, ect…
Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

****************************

Next,
Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
heres my log from malwarebytes: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4265 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 7/1/2010 12:23:25 PM mbam-log-2010-07-01 (12-23-25).txt Scan type: Quick scan Objects scanned: 121624 Time elapsed: 3 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 10 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 4 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\QNB2EB90WX (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\RZDVL2F27W (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallWTF1012$ (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\$NtUninstallWTF1012$ (Adware.EZLife) -> Quarantined and deleted successfully. C:\Documents and Settings\Joey Harter\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully. C:\Documents and Settings\Joey Harter\Application Data\Street-Ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully. C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\$NtUninstallWTF1012$\elUninstall.exe (Adware.EZLife) -> Quarantined and deleted successfully. C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
wow, so from the looks of this log, every infected file was deleted successfully?? does that mean i'm 100% clean now?? ****EDIT****** damnit… i was wrong. even after all of the scanning and deleting of files, i still just got a pop up from avira saying: "A virus or unwanted program 'TR/Crypt.XDR.Gen' was found in file C:\WINDOWS\Temp\rfpi.tmp\svdhost.exe" access to this file was denied Please select a further action: [remove] - [details]" i always click the remove button but it always comes back. :( *****EDIT #2******** Also just got a pop up add out of nowhere
Okay time to bring out the big guns…

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.
after downloading and attempting to run the combofix.exe, i get this error message.

http://img535.imageshack.us/img535/8186/combofixerror.jpg

the box below is what i get when i click on "for more information about this error, click here" and the box on the right is what comes up when i click on "to view technical information about this error report, click here" on the lower box.

i tried it 4-5 times and the same thing happens every time!! no clue why its doing that. ive disabled my avira program from booting up on startup so there are no conflicts. no other anti-virus, anti-malware, or firewall programs are running. any ideas?
grrr whenever i try to google something related to trying to fix this virus, the links just redirect me to some wierd search engine/spam add website instead of the site that is shown on the google search. so frustrating!! i cant search for any information to help me learn. AND WOW as im typing this, another fake anti virus called "sysinternals antivirus" just tried to force itself to install and 4 pop ups came up…. TWICE… dayam this is so annoying. i think i might have just got another/more trojans or malware…
You're definitely still infected, and there has probably been a rookit there all the time, hiding things. Sometimes when you start to "pull the rug out" from under it by deleting files and such it rears its' ugly head. Hang in there, we'll do our best to get it. If Safe Mode doesn't work. Delete the copy you downloaded and try downloading a fresh copy. See if that helps. Edit for typo.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI