TrojanDownloader.xs (trojan-downloader.xs)

TrojanDownloader.xs or also known as Trojan-Downloader.xs is a threat being displayed on security warning pop-up messages generated by rogue antivirus application. The said rogue program was installed on computer without users consent via Trojan Zlob and misleading security websites. Malware that brought TrojanDownloader.xs on to the computer will exploit software and system vulnerabilities to get inside.  Once loaded, the Trojan will modify Windows registry that will allow itself to run automatically when the system has started.  

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

How to Remove TrojanDownloader.xs:

FIRST AID TO STOP TrojanDownloader.xs:
If a virus have infected the system, registry and legitimate Windows files are also compromised. System Restore can reinstate clean system files by restoring the configuration to an earlier date. If a restore point was created before you got infected with TrojanDownloader.xs, please restore Windows to previous configuration.

REMOVAL TOOL for TrojanDownloader.xs:
1. Download Malwarebytes’ Anti-Malware (mbam-setup.exe) and save it on your Desktop.
2. After downloading, double-click on the file to install the application.
3. Follow the prompts and install as “default” only
4. Before the installation completes, check on the following prompts:
- Update Malwarebytes’ Anti-Malware
- Launch Malwarebytes’ Anti-Malware
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.
6. Scan your computer thoroughly.
7. When scanning is finished, click on the “Show Results”
8. Make sure that all detected threats are marked, click on Remove Selected.
9. Restart Windows.

Note: TrojanDownloader.xs may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.

MANUAL REMOVAL OF TrojanDownloader.xs:
1. Update installed anti-virus application to have the latest definition file.
2. Reboot Windows in Safe Mode
- After turning on the power, press F8 on the keyboard.
- Select Safe Mode from the menu.

3. Thoroughly scan the system and clean/delete all infected file(s).
4. Exit registry editor and restart Windows.

ADDITIONAL TOOLS AND PROGRAMS:

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove virus and unfamiliar threats without using the traditional AV signatures. Download the tool and start scanning with Norton Power Eraser.

Technical Details and Additional Information:

Other functionalities of this Trojan:
- Display commercial advertisement.
- Connects to a remote server to download more files.
- Stays hidden in the background.