Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the trojan around my pc till it has ended up in my system restore(bloody typical)ive shut down my system restore and cannot still access the file to delete it.....its in c:\_RESTORE\TEMP\A00034787.CPY Ive tried to locate it through file finding but it says i have typed in the file wrong or the search comes up as blank.....ps i have tried to locate it through safe mode with my system restore off but to no avail.ive even tried to do a system restore but my pc wont let me go any further than yesterday!!!!!! any suggestions would be greatly appreciated!.....ps i can access the internet with no probs xxxxxxx

Have you thrown any AV or Trojan detection/removal "program(s)" at it?
And...if you disable System Restore,ALL previous restore points will be lost.

Ok, I'm not sure what you are saying about your system restore. Did you "disable" it like this:
Go to Start|Settings|Control Panel. Double-click 'System', then click on the 'Performance' tab.
Click 'File System' then click the 'Troubleshooting' tab. Select 'Disable System Restore' and click 'Apply'.
Now uncheck 'Disable System Restore' and click 'Apply'. Click 'Close' and click 'Close' again.
Restart the computer.If that's what you did the restore file it was hiding in has been purged.
You also need to dump your TIF files, cookies, %TEMP% files, recycle bin.
Go here:
http://swatit.org/download.html
and download SwatIt, it's free, (was when I used it...), and it works.
Now, if it gave you a file name, like, "Downloader.Swizzer.whatever"
shut down and come back in Safe Mode, and run 'search files and Folders, and if it's there, delete it. Run your AV in Safe Mode, and run SpyBot and Adaware in Safe Mode. If you don't have them, do this:
Spybot:Download and Read the SpyBot tutorial here:
http://s89223352.onlinehome.us/mirror/spybot/index1.php
Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.
Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes. You’ve got two measely minutes and it’s worth it, and let Spybot run if it indicates.
To add an item to your ‘Ignore List” click on the little ‘+’ sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.
When you are done reboot again same way. Two full minutes shut sown is best.
Tea Time discussed by designer here:
http://forums.net-integration.net/index.php?showtopic=13433
Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on ‘search for updates,’ the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.
Ad-Aware:Download AdAware from http://www.lavasoft.de/
check for updates at "webupdate".
I use these settings (green check)
From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.
Put a black dot nest to "Use custom scanning options” and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"At the top of the “STATUS” page notice the Tweak (gear) icon. Click on it.
The first setting is “Scanning Engine.” Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and “include basic Ad-Aware settings in log file”. Next click on the ‘+’ next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring”
Click "proceed", that will save those settings.
Click "Scan"
When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press ‘next’ and then ‘yes’ to the prompt: “remove all these entries”.
However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do it’s job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on ‘ignore list.’
Shut down, two minute shut down is best, and let Adaware run on reboot if it indicates.
Here's a downloading tip, I do this:
One other thing I do is on downloading, after you get the download (M$ does not structure its downloads so you can do this for some reason), after download BEFORE INSTALL, #1. log off the net, #2. disable AV (right click tray icon), #3. then ctrl-alt-delete to close AV in close-program, THEN (and only then) #4. click on the install procedure. Otherwise your AV might read the install as an invader and mess with it. Then manually shut down for two full minutes.
That should keep you busy for an hour or so.
After SWATIT and running AV, Adaware and Spybot in Safe Mode, you come up clean, then that should be it. Re-enable yours system restore, set a check point if it didn't automatically do it for you.
If you feel a HiJackLog would be a help, download it here:
http://www.lurkhere.com/~nicefiles/
and post it on this site or post it here:
http://forums.spywareinfo.com/
Thresher

thanks so much for your replies........ive done all you have said and it seems to have worked....all scans say my pc is free of the trojan!!!! the only prob i still have is i still get an error message "explorer has caused an error in unknown" this may suggest that i have a corrupt or damaged cpl file in my windows explorer. any suggestions how to fix it? regards linda xxx ps thresher it did keep me busy for a while and many cups of tea(cheers)
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Try replacing explorer.exe. Get yourself a new one from your cab files. Follow the instructons that apply to extracting explorer.exe from response #4 in this post.
http://www.computing.net/windowsme/wwwboard/forum/42790.html
You can do it in windows through msconfig by clicking the "Extract File" button, but try that first.
If it's not an explorer.exe problem, then "unknown" is a big place -- and more details and observation would be required.

You don't mention if you are updated on everything...windows, IE AND Outlook even if you don't use it, Outlook's settings will affect IE. Is your Me updated? If not go to windows update and get it done. If you want to re-install IE, go here: (I would)
http://www.microsoft.com/windows/ie/downloads/critical/ie6sp1/default.asp
remember to update your AV, Spybot, and Adaware every 3 days, and run them no less than that.
Keep your TEMP Files, TIF and cookies and recycle bin clean.
Thresher

Depending on what IE your on, try repairing it before re-installing it. Re-installing IE is a big step and isn't always smooth or successful.
So the things to try first are the non destructive things -- replace explorer.exe, repair IE. Then, try the re-install of IE.

ok i went to response number 4 as you said and loaded my boot disk and clicked on "boot in dos" all the commands that were suggested were thrown back at me as "bad file name or bad command prompt"......shall i just give in and totally restore?
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

I'm guessing your maybe on about a recovery boot disk (?). If you use an ME startup disk and boot with it and choose "with cd support" and get to A:\>prompt, you would have been good to go with the commands in #4.
Not a problem though. Boot into windows like you normally do and go to >> Start >> Run >> and type, msconfig and click ok.
Click the "Extract File" button and put explorer.exe where it says "Specify the file you would like to restore". Click Start.
In "restore from" put:
C:\WINDOWS\OPTIONS\INSTALLIn "Save file in" put:
C:\WINDOWSClick Ok. It will probably ask you if you want to make a backup and save it to a specific loctaion. Say yes. Once the files been extracted, run the machine for a bit and see if it resolves the explorer error message.
If the process won't let you extract the file, post back. Couple of things you can do.
If it does and it doesn't solve the error message then try repairing Internet Explorer.
Post back with the results of those two before you totally reinstall IE or you re install. Maybe more you can do.

I think that I have a very efective and easy method for you to take these trojans out.
Remove the contaminated drive, whether from laptop or desk top connect this drive to another PC best to use master slave channel.
Make sure that the PC you are using has an upto date AVG antivirus, and try to have it with NTFS file system, then all you have to do is to use this PC to scan the infected drive, this worked very well for me on a clients PC, the reason I believe it was so successfull is that you are not opening the contaminated drive,All the best folks any probes email me
stallturn@msn.com

thanks all for your patience!!! ok ive managed to extract the explorer.exe file and saved to to c:\ and im now supposed to drag the explorer folder to where i extracted it from. i was working in safe mode and it says i cannot move the file as its in use, so therefore i cannot as yet over write the old file.....ps what do i type in to the exrtact box to get a new copy of internet explorer?.........im still banging my head lol but i think i will get there in the end..pps sometimes now my error message comes up as a kernal32.dll error especially when ive just re-started!!!
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Instructions are as above in #8 Linda.
You extract the file, explorer.exe, from C:\WINDOWS\OPTIONS\INSTALL (those are the cab files) directly to C:\WINDOWS and in the process, over write the old explorer.exe.
Hence me putting.
Boot into NORMAL windows and go to >> Start >> Run >> and type, msconfig and click ok.
Click the "Extract File" button and put explorer.exe where it says "Specify the file you would like to restore". Click Start.
In "restore from" put:
C:\WINDOWS\OPTIONS\INSTALLIn "Save file in" put:
C:\WINDOWSClick Ok. It will probably ask you if you want to make a backup and save it to a specific loctaion. Say yes. Once the files been extracted, run the machine for a bit and see if it resolves the explorer error message.
And me then putting:
"If the process won't let you extract the file, post back. Couple of things you can do."
But by the sounds of it you haven't extracted explorer.exe to C:\WINDOWS but to C:\ ...and then tried to manually put it somewhere or drag something to it.
None of which I posted in the original instructions. You made that up :)
Doesn't work like that. Try the instructions again in windows (not safe mode), it takes approximately 2 minutes maximum to extract and replace a file by using msconfig.
Take your time and read the insttructions again and then take your time and read what's in front of you when your doing it.

http://support.microsoft.com/default.aspx?scid=kb;EN-US;265371..............C:\windows\options\install didnt work as my windows was installed by the maufactures. so i was looking on the microsoft page as how to access a file that was protected by windows, anyways i will get there eventually...thanks for you support
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Hi Linda,
Did you try putting:
C:\WINDOWS\OPTIONS\CABS
Or just plain old.
Win_16.cab
Instead of C:\WINDOWS\OPTIONS\INSTALL ?
Try those two first.
I had a feeling you'd say it was an OEM machine, some are worse than others for b---tardizing windows. Just keep posting back telling us where your up to :)

hey viking!!!! no look with the extracting as yet but something else ive noticed when i goto tools on my explorer page then to options, then to advanced and uncheck 3rd party browser extensions and if i dont re-start i can access my files np probs but if i do re-start my settings go back to the 3rd party box as being "checked" also i have a file in my c:\windows that appears again after ive deleated it! little crettin its called "internet blue" and dosent seem to contain anything!!! i now have several virus/trojan removal tools and apparently my pc is clean (ps i love the word you used b---stardizing) i know its the easy way out to do a total restore but i dont want this piece of wires and microchips to get the better of me..well yet anyways.xxxx
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Nice one for not quitting and taking the easy way out :) don't blame you, plus you learn a little.
Ok, quick recap.
Try these things again even though you've done them (some) before.
Disable system restore and re scan with an online virus scan. Panda Active Scan
Do the reverse instructions to reenable system restore, obviously.
Make sure Spybot S&D and Ad-Aware 6 are fully updated and run them again.
Then Goto Start >> Settings >> Control Panel and click "view all Control Panel options" If everything is already showing.
Then find, Folder Options >> View >> Uncheck "Hide protected operating system files (recommended)"
And uncheck "Hide file extensions for known file types"
And put a dot in "Show hidden files and folders"
Rebooting where asked, if not asked -- reboot anyway.
Now repair Internet Explorer.
1. Click Start, point to Settings, click Control Panel, and then double-click Add/Remove Programs.
2. On the Install/Uninstall tab, click Microsoft Internet Explorer 5, click Add/Remove, click Repair the current installation of Internet Explorer, and then click OK.
Now the explorer.exe extraction. Try going through the msconfig extraction routine now. In the restore from bitPut:
C:\WINDOWS\OPTIONS\INSTALLFailing that, use:
C:\WINDOWS\OPTIONS\CABSand failing that, finally use:
Win_16.cabDo you get a clean extraction of the file ?
After that, your options are to either reinstall Internet Explorer or totally reinstall the Operating System by using your recovery disk. See where the above gets you first though Linda.

hiya viking!!! hope your well? ive given up on the replacing files thing......but i have noticed if i goto tools on my explorer bar, then to internet options and then advanced and uncheck the 3rd party box i can access my files no-probs but when i re-start the box is automatically checked again and i cannot access anything........i have lots of anti this and anti that programs that show my system is clean as a whistle if i run them on safe mode or normal.....ps i love the word you used "b--tardizing"
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Linda:
Do this please:
http://www.microsoft.com/windows/ie/downloads/critical/ie6sp1/default.asp
Just reinstall the IE6--SP1, with respect to Viking, but I have never had a problem with anyone doing this, and it takes about 6--8 minutes depending on your dwnld speed.
BTW, I think if you look closely the IE 6 exe file is EXPLORE.EXE, not EXPLORER.exe.
Just reinstall it.
Thresher

Thresher,
"BTW, I think if you look closely the IE 6 exe file is EXPLORE.EXE, not EXPLORER.exe."
Hmmm, I think, if you look closely it's "IEXPLORE.EXE"
That's at;
c:\program files\internet explorer\iexplore.exeAnd the one in question, that linda is replacing is "EXPLORER.EXE"
That's at;
c:\windows\explorer.exeBut, that's just an opinion.
CrazyOne
p.s. 194177 Description of the Internet Explorer Repair Tool

linda walker,
Could you give the exact error messages, you're getting, please. And if there is a button, on that error message [Details] ect. click it, to find out more info. That's if it's present, ok.
CrazyOne
p.s. Your response No.3, is this, what you were talking about? Just a guess, mind you.time for some ZzZzZzZzZ's ;-)

Thanx for pointing the obvious out CrazyOne, It's needed sometimes.
Here's my simplistic early morning approach.
Thresher, I'm thinking you've consistantly missed the point here."i still have is i still get an error message "explorer has caused an error in unknown"
Seeing as though large chunks of Internet Explorer and Windows Explorer are fully integrated in Windows, It's fair to say that they are one of the busiest working modules around. This makes them prone to corruption, very prone to error messages appearing -- Lots of internal traffic and lots of things potentially butting heads and jostling with each other.
Not surprising that the system gets a jolt or kick in the pants after an infection by a virus or A another and subsequent clean up rountine. Things can go a little askew.
Now you can choose a sledge hammer to crack a nut approach, or you can use all the tools in your armoury to resolve issues, It depends on just "what" you have available to you ...and of course, IF, you choose to use them.
By doing the above (#15) your using the tools and options available to you in a non destructive, sequential order.
Just because you personally have never experienced any issues involving an IE reinstall doesn't mean that they don't happen or exist. Forums are (more were at one point) strewn with failed IE Installs/downloads and people claiming that they had to try multiple times to get IE on straight and not have it behave like a misfiring synaptic malfunction.
Where's the smart money gonna go ?
With a one shot deal like reinstall IE, that potentially could go wrong and the OP (Original Poster) having NO clue how to deal with it and panicing because they aren't able to do anything about it because they no longer have a working browser with which to communicate with.
OR,
Working your way through alternatives, before, arriving at a reinstall of anything. And I include the OS in that.
I could go on but I've managed to bore myself to death -- the glass eye was already asleep.
Linda :) I'm guessing by the tone of your post, that you cheated and used the recovery disk. Which is cool, that's what such things are there for -- as a last resort, or when your bored of messing. :)BTW, if you'd have tried doing the folder options in #15 you may well have had some joy. Equally with reinstalling IE. But that's not what the crux of this thread was about. Was it.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |