My problem explained with logs.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lockridge, Nov 16, 2008.

  1. lockridge

    lockridge Private E-2

    So ive today my computer starting acting up, It would just restart over and over etc. So I eventually downloaded Avira AntiVir Personal and got these errors:

    C:\WINDOWS\system32\Karna.bat TR/Crypt.XPACK.Gen
    This was all the time, when I started, when I tried to run a program etc.

    I also occasionally got these

    brastk.exe

    c:\WINDOWS\system32\drivers.sus TR/Rootkit.Gen

    So I looked up the "Karna.bat" in google and got this forum so I went through all of the stickied instructions with my logs, I ran Malwarebytes-Antimalware program first and seemed to clean up alot of it, stopped getting most errors and my computer seems to be running fine now, but I will post logs.
     

    Attached Files:

  2. lockridge

    lockridge Private E-2

    Last log.
     

    Attached Files:

  3. lockridge

    lockridge Private E-2

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You really should read all of the sticky threads. This bump cost you additional waitinging time. See: Don't Bump! It Only Hurts You!!!

    Your logs show that you had a lot more problems then just the TR/Crypt.XPACK.Gen infection you mentioned. And you have more to fix. However first you MUST put your PC into normal startup mode with MSconfig as we requested in step 1 of the READ & RUN ME. Then continue on with the below.

    Disable Spybot's Teatimer as requested in the READ & RUN ME.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. lockridge

    lockridge Private E-2

    Sorry about the bump, I honestly didnt see that sticky. Thanks for the reply. Ill get to work.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This thread will be closed soon if there is no reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds