'TR/Crypt.ZPACK.Gen [trojan]' and 'WORM/Rimecud.A.825 [worm]'

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jhill150, Feb 16, 2010.

  1. jhill150

    jhill150 Private E-2

    Hi,
    I very much appreciate what you guys do and do not want to abuse the opportunity. My avira reported on two malware items a few times in over two days, which kept going into temporary folders. AVira denied access but they kept reappearing. I then put them in quarantine. I did a search, and the trojan was reported as quite troublesome, so I ended up in your site and followed all the guidelines. I can't say that I have a problem that I am noticing, but I did see that the combofix log says I might have an MBR rootkit, so I am posting this. If you feel from what I have told you that I should just wait until I actually see problems, I'll do so and then you won't have to waste your time reading my logs.
    The malware originally found by avira:
    'TR/Crypt.ZPACK.Gen [trojan]'
    'WORM/Rimecud.A.825 [worm]'
    After I put them in quarantine and then erased the quarantine as per your guide, I haven't seen any reports of them.
    My logs are attached.
    This all happened ironically one day after I purchased and installed malwarebytes pro version. From your malware prevention guidelines, it seems to suggest that I should not have malwarebytes and avira real protecton simultaneously, but the malwarebytes site says that they are complementary.
    I disabled system restore when I started, and I now realize that you did not want me to do that, but the bottom line is I don't have it so don't ask me to use it.
    One last thing: I have not found on your site what the best thing to do when a virus program such as avira reports finding malware. Do we put it in quarntine? delete it? deny access? how should I configure the default program action?
    thank you very very much. It is very kind that you provide this service.
     

    Attached Files:

  2. jhill150

    jhill150 Private E-2

    two more attachments to this thread
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix directly on your desktop, not here:
    Running from: d:\my documents\downloads\ComboFix.exe ---> it should be here:
    C:\Documents and Settings\Aba\Desktop\ComboFix.exe

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    I am not seeing any malware or MBR infections in your logs. You need to tell me exactly what Avira is reporting......the exact paths!
    But you have since removed them from quarantine. You did the right thing to quarantine them. So I can only suggest that you keep Avira updated as well as your other AS programs.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. jhill150

    jhill150 Private E-2

    thank you.
    I cleaned up the desktop. Only links are there now.
    I have compiled all of the warnings that had received from avira and listed them in a text file attached.
    No longer getting messages from avira.
    When the problem started, I disconnected my external hard drive. What is the best procedure for testing it when I reconnect? Just disable autorun and then scan with malwarebytes and avira?
    I discovered that I had windows defender on my computer, must have installed it a while ago. I have now uninstalled it, unless you suggest I keep it. I have read your file on protectioni and if I understand it correctly, the following combo is a good one: malwarebytes pro (realtime protection which I bought), avira antivirus, and spybot with the teatimer disabled. is that right?
    in general, is quarantine the correct choice for any warnings?
    thank you for your help.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off, you are most welcome.

    Now, I suggest that you also keep SAS. The rest of what you have is fine. Windows Defender will not harm anything if you want to keep it. Quarantine is the best way to go, as sometimes what is removed could be a false positive and do harm, so you want to be able to restore items in quarantine if such an occurrence happens. :)

    I suggest you install this:
    AutoEater.

    Then make sure all your protection software is up to date. Then run MBAM, SAS, and then Avira on that external drive.
     
    Last edited: Feb 18, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds