Hello! I have a trojan called tr\crypt.xdr.gen. I have scanned with mcafee, ad-aware, avira anti-virus, and advanced system care, yet none of them have removed the virus entirely. I get a notification from my avira saying it has blocked the "tr\crypt.xdr.gen" trojan. sometimes every 5-15 minutes, sometimes i wont get it for over an hour. Here is my hijack this log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:46:24 PM, on 6/30/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\program files\steam\steam.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
–
End of file - 2139 bytes
—————
ive also seen a few forum posts on here about the same virus saying to scan with the kaspersky online scanner and include that log also, so i went ahead and did that. Here is my kaspersky online scanner log:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, June 30, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, June 30, 2010 22:55:04
Records in database: 4263627
——————————————————————————–
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Objects scanned: 65602
Threats found: 7
Infected objects found: 8
Suspicious objects found: 0
Scan duration: 01:33:09
File name / Threat / Threats count
C:\Documents and Settings\Joey Harter\Local Settings\Temp\bxwn.exe Infected: Trojan-Downloader.Win32.Mufanom.vjo 1
C:\Documents and Settings\Joey Harter\Local Settings\Temp\qodigx.exe Infected: Packed.Win32.Krap.ao 1
C:\Program Files\ESEA\ESEA Client\eseaclient.css.dll Infected: Backdoor.Win32.Turkojan.hvn 1
C:\Program Files\ESEA\ESEA Client\eseaclient.tf2.dll Infected: Backdoor.Win32.Turkojan.hvm 1
C:\Program Files\NN MiRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Program Files\Trend Micro\HijackThis\backups\backup-20100629-181402-197.dll Infected: Trojan.Win32.BHO.ahuh 1
C:\WINDOWS\dinwmql.dll Infected: Trojan-Downloader.Win32.Mufanom.vjn 1
C:\WINDOWS\system32\tjxrt.dll Infected: Trojan.Win32.BHO.ahuh 1
Selected area has been scanned.
————————
I am tempted to go ahead and delete all of these files that are infected manually since kaspersky has given me the direct file path, but i will just wait to hear from someone on here to tell me what to do. thank you VERY MUCH in advance and i hope to be able to fix my computer without having to reformat.
Hello IndiGenus!! thanks so much for replying. no, i havnt deleted any of those files, so i would like it if you gave me a tool to help do that. when i'm done doing that, i'll take the next step by following the instructions on that other page you linke me to
Do you use or know of the ESEA program on your computer? Looks like some kind of anti-cheat engine? Kaspersky flagged files from that along with the mIrc which is a false positive. I'll leave those for now.
Please downloadOTM by OldTimer.
Save it to your desktop.
Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
yes, i do use the esea program from time to time and yes it is a counter-strike anti-cheat program. but if there is a trojan being detected in there, i have no problem removing that program since i dont use it enough anyways.
Here is my old timer log:
All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
========== FILES ==========
C:\Documents and Settings\Joey Harter\Local Settings\Temp\bxwn.exe moved successfully.
C:\Documents and Settings\Joey Harter\Local Settings\Temp\qodigx.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\dinwmql.dll
C:\WINDOWS\dinwmql.dll moved successfully.
C:\WINDOWS\system32\tjxrt.dll moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Joey Harter
->Temp folder emptied: 109929853 bytes
->Temporary Internet Files folder emptied: 22072836 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 856432 bytes
->Flash cache emptied: 1072 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 80413 bytes
->Flash cache emptied: 596 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 18585377 bytes
->Flash cache emptied: 10462 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1138618 bytes
%systemroot%\System32 .tmp files removed: 2891281 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 361630 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34105 bytes
RecycleBin emptied: 20171538 bytes
Total Files Cleaned = 168.00 mb
OTM by OldTimer - Version 3.1.12.2 log created on 07012010_115724
So, whats next sir?
yes, i do use the esea program from time to time and yes it is a counter-strike anti-cheat program. but if there is a trojan being detected in there, i have no problem removing that program since i dont use it enough anyways.
No, it's a false positive by Kaspersky. Just by the nature of the program it has behavior like Malware. Same with mIrc. They can be left.
Please follow the instructions at the link I gave earlier and post the DDS logs. Let me know how it's running now too please.
Another good free scanning program is MalwareBytes. I would suggest you download, update it, and run a scan.
First, Use ATF Cleaner to remove temp files, cookies, cache, ect…
Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button. If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
****************************
Next,
Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and Paste the entire report in your next reply.
wow, so from the looks of this log, every infected file was deleted successfully?? does that mean i'm 100% clean now??
****EDIT******
damnit… i was wrong. even after all of the scanning and deleting of files, i still just got a pop up from avira saying:
"A virus or unwanted program
'TR/Crypt.XDR.Gen' was found in file
C:\WINDOWS\Temp\rfpi.tmp\svdhost.exe"
access to this file was denied
Please select a further action:
[remove] - [details]"
i always click the remove button but it always comes back.
*****EDIT #2********
Also just got a pop up add out of nowhere
the box below is what i get when i click on "for more information about this error, click here" and the box on the right is what comes up when i click on "to view technical information about this error report, click here" on the lower box.
i tried it 4-5 times and the same thing happens every time!! no clue why its doing that. ive disabled my avira program from booting up on startup so there are no conflicts. no other anti-virus, anti-malware, or firewall programs are running. any ideas?
grrr whenever i try to google something related to trying to fix this virus, the links just redirect me to some wierd search engine/spam add website instead of the site that is shown on the google search. so frustrating!! i cant search for any information to help me learn.
AND WOW as im typing this, another fake anti virus called "sysinternals antivirus" just tried to force itself to install and 4 pop ups came up…. TWICE… dayam this is so annoying. i think i might have just got another/more trojans or malware…
You're definitely still infected, and there has probably been a rookit there all the time, hiding things. Sometimes when you start to "pull the rug out" from under it by deleting files and such it rears its' ugly head. Hang in there, we'll do our best to get it.
If Safe Mode doesn't work. Delete the copy you downloaded and try downloading a fresh copy. See if that helps.
Edit for typo.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI