TR.Crypt.FKM.Gen infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by NoGeekMe, Oct 27, 2008.

  1. NoGeekMe

    NoGeekMe Private E-2

    Greetings!

    Hope some helpful MG can take a look and see if my logs are clean; I ran the Read and Run Me after Avira reported occurrences of TR.Crypt.FKM.Gen.

    Add'l info:

    When ComboFix was running it reported that it had detected root kit activity and asked for permission to re-boot (which I gave it).

    Coinciding with running Combo Fix an error message for WordPerfect Office 12 started popping up out of the blue. I forgot to copy the text from it, but basically it says the file that's needed is on an installation disk, please install the disk. When I hit cancel I get error message 7016 (I think!?). I have no disks for WordPerfect, it was installed on the PC when I got it.
     

    Attached Files:

  2. NoGeekMe

    NoGeekMe Private E-2

    TR.Crypt.FKM.Gen infection - - rest of attachments

    MGtools zipped logs attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi, we are looking your logs over and will get back to you as soon as we possibly can. Thanks for your patience.
    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi your logs are clean :)

    Just this to do:

    1) Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Then..

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. Go to add/remove programs and uninstall HijackThis.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
    Last edited by a moderator: Oct 27, 2008
  5. NoGeekMe

    NoGeekMe Private E-2

    That's reassuring, thanks for your help, Kes13!

    One issue is left. When I re-booted I got Windows Installer again - - mysteriously trying to install a WordPerfect feature. This started yesterday, after running ComboFix.


    Please wait while Windows configures WordPerfect Office 12


    then:

    The feature you are trying to use is on a CD-ROM or other removable disk that is not available.

    Insert the 'WordPerfect Office 12' disk and click OK.


    then, after selecting 'cancel':

    WordPerfect(R) Office 12
    Error 1706.No valid source could be found for product WordPerfect Office 12. The Windows Installer cannot continue.


    Do you know how I can fix this? Also, jsut curious, was the ComboFix screen message about detecting root kit activity a glitch?

    Thanks!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs it would not seem that this is related to ComboFix or any of the other scans. None of them found or removed anything. We can see this from the logs for each scan. That is unless Spybot found and removed something. Attach the last log from Spybot which you should be able to find in the below folder.

    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs


    Also please attach the below files:
    C:\Qoobox\ComboFix2.txt
    C:\Qoobox\ComboFix-quarantined-files.txt


    The only possible work around that I can think of for this issue with Windows Installer and Wordperfect is to use System Restore to go back to a point in time before you ran ComboFix on 10-27-2008.

    Didn't Dell give you a CD with your PC that contains this program and all other installed on the PC? If not, I guess they just foolishly expect that anytime someone has a problem that they will have to restore the PC to the way it was shipped which is not what anyone would want to do. By the way do you use Wordperfect?


    As stated above, nothing was found based on the logs so I'm not sure what this message is really about.
     
    Last edited: Oct 28, 2008
  7. NoGeekMe

    NoGeekMe Private E-2

    I've uploaded the Spybot log.

    Already ran the 'final steps' in last message from Kes13, so don't have qoobox or old restore points.

    Googling turned up a few people with the same WordPerfect/Windows Installer issue following malware/malware removal software.

    I don't use WP often on this machine, but I like knowing it's there, it's my preferred ap for very long documents.

    WP itself seems to be OK, just the annoying Windows Installer popping up out of the blue. It would be great if there's a way to stop it. I don't have WP disks, the machine was a hand-me-down.

    Thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you did not get it attached. ;)


    You may be able to work this out in the Software Forum. It may be possible that something will show up in an Event Log on this. You could also check to see if the below application can help:

    Windows Installer CleanUp Utility
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds