QUESTION- TR/Crypt.ZPACK.Gen & Firefox

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sebastian3297, Oct 30, 2009.

  1. Sebastian3297

    Sebastian3297 Private E-2

    A few hours ago i made a purchase with a credit card, then i stupidly downloaded some files :)banghead )...and got TR/Crypt.ZPACK.Gen...as we all know, firefox likes to store things you write into text boxes...the CC# was stored by FF...could the trojan have possibly gotten to the # stored in the FF files? I'm really nervous! Please tell me if i can be in SERIOUS trouble(because i'll have to call my bank) please reply to me fast! I noticed you guys go by certain standards here but i really need information on this trojan and fast!

    :cry

    Best Regards,

    Sebastian

    PS. Antivirus was Avira e9. The trojan is gone now.
     
  2. Sebastian3297

    Sebastian3297 Private E-2

    chaslang. I've noticed your the guy to go to here, if you can tell me anything it would be greatly appreciated :(
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Show us a log from Avira so we can see what it removed. Also we recommend that you run our cleaning procedure so we can be more certain you are clean. See the below:

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. Sebastian3297

    Sebastian3297 Private E-2

    Here are the two removal logs from avira.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You definitely need to run the cleaning procedure.

    Was the UnknownPK.rar file what you downloaded?
    If so, where did it come from and did you extract anything from the RAR?
     
  6. Sebastian3297

    Sebastian3297 Private E-2

    I downloaded a game, apparently someone felt like throwing in a couple of extra files...I can't find the link where i downloaded it from, it extracted a couple of folders, 1 .exe and .dll. I didn't touch anything because of the warning by avira.

    BTW, i've scanned with avria, malware bytes and MS malware removal and its all clean so far. Running ComboFix.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run all steps in the procedure I gave you in the order given. SUPERAntiSpyware needed to be run as the first scan and there are other preliminary steps to complete first. Then you need to attach all 5 requested logs at the end whether anything is detected or not.
     
  8. Sebastian3297

    Sebastian3297 Private E-2

    Sorry, i'm running SUPERAS now.

    Quick Question...can a Trojan know what you've done in your computer before it actually enters the system?
     
  9. Sebastian3297

    Sebastian3297 Private E-2

    Some logs and please look at the JPEG file...I don't know what to do about that...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing! As stated in the procedure, you were supposed to shutdown your protection before running ComboFix.

    You did not update MBAM to the current database. You are more than 300 versions out of date. Also since you never installed all of your Windows Updates, you have a Conficker infection. You need to finish running ComboFix and SUPERAntiSpyware. They needed to be run BEFORE MGtools so you will have to run MGtools again and attach a new log. As stated previously steps must be followed in the order written.
     
    Last edited: Oct 31, 2009
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean by this question since it could be asking two different questions, so I will answer it two different ways.
    1. If a trojan is not on your system then obviously it does not know what you are doing.
    2. If you get a trojan that attempts to collect personal information then yes it could look at things you had done in the past.
     
  12. Sebastian3297

    Sebastian3297 Private E-2

    Should i start calling the bank then? :(
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to be 100% sure you are safe yes.

    You also need to do what I previously stated about running all tools in the proper order and getting updated versions of the programs. And then run new scans and attach new logs. Otherwise you need to format and reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds