Cant Remove TrojanDownloader.NX [RESOLVED], Computer running slow, windows security center says i have TrojanDownl |
Cant Remove TrojanDownloader.NX [RESOLVED], Computer running slow, windows security center says i have TrojanDownl |
Jan 17 2008, 12:29 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Hello,
Im new here and have a problem. Windows security center says i have a TrojanDownloader.NX on my computer and must remove it. There is a link to go to and its just a bogus website. There is also a yellow triangle in the taskbar and when ever i click on it it goes to the same website. Aslo, their is a different Windows Security Center message (its red) and says their is a specific spyware on my computer. I dont know what to do. I run spybot as well as webroot spy sweeper and it picks up nothing. I downloaded HijackThis v2.0.2 and heres a recent log. Also, my task manager does not work and says it has been disabled my the Administrator. Please Help!!!!! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:29:01 PM, on 1/17/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\qiawpbjj.exe F:\WINDOWS\system32\devldr32.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe F:\PROGRA~1\mcafee.com\agent\mcagent.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\Program Files\iTunes\iTunesHelper.exe F:\WINDOWS\System32\CTsvcCDA.EXE F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\Program Files\Messenger\msmsgs.exe f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\WINDOWS\system32\ctfmon.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe F:\WINDOWS\System32\MsPMSPSv.exe f:\PROGRA~1\mcafee.com\vso\mcshield.exe F:\Program Files\iPod\bin\iPodService.exe F:\Program Files\Webroot\Spy Sweeper\SSU.EXE F:\Program Files\Trend Micro\HijackThis\HijackThis.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F:\WINDOWS\system32\winlogon.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe F:\WINDOWS\system32\wuauclt.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F2 - REG:system.ini: UserInit=F:\WINDOWS\system32\qiawpbjj.exe,F:\WINDOWS\system32\userinit.exe O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {66E72884-4FD2-464F-A6B8-468F31C40E36} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [KernelFaultCheck] F:\WINDOWS\system32\dumprep 0 -k O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [AIM] "F:\Program Files\AIM\aim.exe" -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [System Support] system32.exe (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe (User 'Sarah McGorry') O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 13187 bytes |
|
|
FX3 Cant Remove TrojanDownloader.NX [RESOLVED] Jan 17 2008, 12:29 PM
Rorschach112 Hello
Download ComboFix from one of the locations... Jan 17 2008, 02:41 PM
FX3 Thanks for your reply.
Heres a log from ComboFix
... Jan 17 2008, 04:38 PM
Rorschach112 Hello
1. Close any open browsers.
2. Open notepa... Jan 17 2008, 05:01 PM
FX3 Thanks again,
Heres the latest HijackThis Log
L... Jan 17 2008, 06:11 PM
Rorschach112 Hello
1. Please re-open HiJackThis and choose do ... Jan 17 2008, 06:19 PM
FX3 Here it is,
Thanks
Deckard's System Scanner ... Jan 17 2008, 06:50 PM
Rorschach112 Hello
Backup Your Registry with ERUNTPlease use t... Jan 17 2008, 07:13 PM
FX3 I got a problem.....
Whenever i try to copy the Ka... Jan 18 2008, 11:42 AM
Rorschach112 Do this instead
Download and scan with SUPERAntiS... Jan 18 2008, 11:46 AM
FX3 It said there was no detections but i remember tha... Jan 18 2008, 01:51 PM
Rorschach112 Your logs look good ! We need to do a few thin... Jan 18 2008, 01:53 PM
FX3 I got a question. Can i uninstall the SUPERAntiSpy... Jan 18 2008, 02:41 PM
Rorschach112 You can uninstall SUPERAntiSpyware if you want, ho... Jan 18 2008, 06:35 PM
FX3 Ok. Just checking. You been a big help the last co... Jan 18 2008, 08:49 PM
FX3 Not to be a nag but i got another problem. My webr... Jan 18 2008, 09:28 PM
FX3 Nevermind, it eventually loaded up. Thanks again f... Jan 18 2008, 10:03 PM
Rorschach112 Since this issue appears to be resolved ... this T... Jan 19 2008, 07:14 AM![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
28 / 11,530 | 19th April 2005 - 12:19 PM panaceabeachbum started - last by ScHwErV |
|||||
![]() |
9 / 893 | 19th July 2005 - 08:22 AM phooey started - last by tampabelle |
|||||
![]() |
10 / 421 | 12th September 2006 - 02:13 AM getz started - last by Crustyoldbloke |
|||||
![]() |
3 / 542 | 25th June 2009 - 04:17 PM Slink started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 12:56 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising