TR/Crypt.XPACK.Gen Detected by Avira, am I clean?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hayjude, Oct 31, 2009.

  1. hayjude

    hayjude Private E-2

    Hey guys, my media server detected the TR/Patched.Gen and TR/Crypt.XPACK.Gen through Avira. I usually am not physically on this server so the logs from Avira (in the post below this as Avira.txt) show a detection from early October onwards.

    I also noticed my hard drive went from having 300GB of space to 20GB after this detection. Turns out a bunch of games I don't own or play were "installed". Avira fired off most warnings with Pro Evolution Soccer 2008.exe which was never installed on this particular PC. Yesterday, when I first realized the problem, it detected the Trojan in two other games I don't own/play. Before reading the forums, I went ahead and deleted the "games" which I know were not supposed to be there. Deleted 100GB+ of data and ran CCleaner to fix Registry issues afterwards. Stumble upon you guys and proceeded to carry out the Vista cleaning procedures. Could it be that the Perp logged in to a Steam account and downloaded these games or is it more likely they are just named after games in order to better disguise their purpose?

    The infected CPU is offline since last night. I am using my laptop to trouble shoot this.

    MSConfig Startup is set to Normal. No UAC. Only AV on machine is Avira Free which had it's guard disabled during all 5 steps of the Vista cleaning instructions.

    1) SUPERAntiSpyware scanned once, went OK, nothing found. Log is attached.

    2) MalwareBytes scanned once, went OK. Log is attached as mbam-log.

    3) ComboFix scanned once, found Rootkit problem within 1 minute and asked for CPU restart. Once restarted ComboFix was executed again by me since no logs were generated from original "problem". Second scan reported no problems and log of it is attached.

    4) Post ComboFix, I couldn't execute any program. Message given was in regards to Registry makred for deletion items. Restarted CPU and all was fine. Fan ComboFix, about 30 minutes in an error occurred. Attached is image of the error. Tried running program again and it just crashed halfway through second scan.

    5) MGTools, have no idea how to interpret it but was executed out of C:\ as asked and attached on the second post is the log.
     

    Attached Files:

  2. hayjude

    hayjude Private E-2

    Attached to this file is the Avira Events History and MGTools log(s).
     

    Attached Files:

  3. hayjude

    hayjude Private E-2

    This is supposed to be about RootRepeal. Sorry for confusion. Again, RootRepeal is the program that provided the error in screenshot and crashed during a 2nd run.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Delete this file: c:\was\ComboFix.exe This is not where ComboFix needs to be. Download the current version to your Desktop as requested so later steps can be completed.


    Actually your logs show quite a few games installed including the ones in your Avira log. If you did not install them then you need to find out who did. There are more than 20 games showing. And you logs also show use of torrent downloading which is most likely the source of infection due to downloading these games. If these are not legal games and there are any cracks or keygens on this PC, you need to uninstall all illegal games and delete all cracks and keygens.

    The below is what I see installed:
    Is the below copy of WinRAR legal? If not, delete it.
    2009-08-08 00:31 . 2009-08-08 00:30 1375783 ----a-w- c:\users\Public\wrar39b5.exe

    Your logs are clean other than all the questionable games which you need to address yourself.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds