TR/Crypt.ZPACK.Gen help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by FishFish101, Dec 26, 2010.

  1. FishFish101

    FishFish101 Private E-2

    Hello, I'm new to the forums, must admit I've lurked for a while and used the fantastic expertise offered.

    I've read through the other TR/Crypt threads but unfortunately nothing worked for me (I must admit I'm fairly poor at understanding the more technical aspects of computing) This is the most complicated virus I've ever had the displeasure of running into.

    Anyway... my AviraAntiVir is picking the TR/Crypt.ZPACK.Gen up every 30 seconds or so and not letting it in. Unfortunately it seems to have made my laptop run significantly slower.
    I have no idea how to begin going about this. It is still there when I restart and I've tried to run CCcleaner to no Avail. And Malwarebytes won't pick anything up.

    I desperately need my laptop fully functioning and I'm terrified that if my laptop goes down that I'll fail my final exams in about a month :(!

    Any help would be appreciated fully... if there's anything I can do to help you please tell me. I know I'm going to probably be asked to post logs, and I'm afraid I'm not fully sure what this means, or how I can do it.

    ANYTHING would be appreciated.
    Huge thanks in advance.
    Regards.
     
  2. FishFish101

    FishFish101 Private E-2

    I do apologize for making a separate thread, this would have been more applicable in one of the existing ones. I'm just panicking so much... lol.
    Anyway I'm reading through the other stuff and doing what little steps I can, but it's slow and not very progressive.
    I also am not experienced enough to start doing things on my own through fear of making it worse.

    Sorry admins, if this is in the wrong place or creating unnecessary work.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there, and a warm welcome to the forums. Sorry to hear about your problems, but I will do my very best to assist you.

    Follow through what you are able to of the below (It will involve you running scans and attaching logs for my reviewal, but the instructions are crystal clear and not confusing.)

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. FishFish101

    FishFish101 Private E-2

    Well took me a couple of hours but I've worked my way through all of that.
    The only thing I didn't run was the RootRepeal and combofix thing... My computer is 32 bit and could apply it, but it went against my better judgement to turn my antivir off in order to run them. This is because so far all that has happened is I get annoying popups from antivir telling me it has located the virus every 30 seconds and made my laptop slower. However it seems the virus hasn't actually got in and affected me yet, so turning the antivir off seems like it would do more harm than good.
    Sorry if I'm wrong, but this went against my better judgement. Please correct me if needed.

    Anyway I've attatched the other logs as requested, hopefully they come through.

    Huge thanks in advance.
     

    Attached Files:

    Last edited: Dec 26, 2010
  5. FishFish101

    FishFish101 Private E-2

    Just to clarify when I open antivir it literally has hundreds of detections for the same thing (the TR/Crypt thing). Like 3 a minute so that's why I didn't turn it off.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are using a version of MGtools that is 3 years out of date. You need to download and run the version given to you in the READ & RUN ME and attach a new log.​
     
  7. FishFish101

    FishFish101 Private E-2

    I'm in Dubai at the moment, and the version in the READ & RUN ME is unacceptable/blocked from this country due to the internet laws. I looked around and couldn't find a suitable mirror. hmmm...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no mirrors and this is the first time I have ever heard of the link being blocked due to internet laws. Rather strange as there is nothing fancy nor unusal about the link or the download.

    You will have to shutdown Avira and run ComboFix. Also it may be helpful if you could attach a log from Avira.
     
  9. FishFish101

    FishFish101 Private E-2

    Could you tell me how to give a log from Avira? I did a scan earlier

    *edit*

    This is freaking bizzare... my Antivir has stopped report it. Like literally for 8 hours that I left my computer on, I came back to 3022 alerts- basically a couple every minute telling me that it blocked the trojan. Now nothing... for like an hour it hasn't detected it once...
    my laptop is running fine... I looked up the symptoms it did to other people. My background is fine, my laptop isn't running slowly. Lots of unknown games and or files haven't appeared on my computer.

    This is either good, or very bad. haha!
     
    Last edited: Dec 26, 2010
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going from memory, so bare with me. Try double clicking your tray icon for Avira. Then select Overview ( usually comes up with this selected ) then click Reports. The it shows a list of Reports. Double click the most recent one and then click the Report file button which will show the report. You can save this somewhere easier to find so you can attach it.
     
  11. FishFish101

    FishFish101 Private E-2

    Good memory haha

    The one I've uploaded was during the day when all was going wrong for me, before the messages stopped. I'm going to perform a scan overnight as I'm heading to bed now. But still not getting any reports now.


    Thanks.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well based on the log from Avira it removed some of these immediately and then scheduled some to be removed on reboot. So perhaps it as able to remove all of them.

    Let me know tomorrow whether you still have any problems after a reboot.
     
  13. FishFish101

    FishFish101 Private E-2

    Thank you very much.

    I've woken up and got this thing at the bottom right hand corner of my toolbar.
    It's a little flag with a red shield with a white x through it. When I click it it comes up with a windows defender pop up.

    I've attatched a picture of it, sorry it's quite big. I've also not done anything and just left it, as I looked up online and have seen people saying it's not real.

    The name of the file, I'm pretty sure was deleted in Malware Malbytes scan, though not 100% sure.

    Thanks in advance, life savers honestly.

    *Edit*

    Well, rebooted, the windows defender thing no longer appears, but the TR/Crypt.zpack.gen virus is back and annoying as ever, Antivir keeps picking it up every 30 seconds or so. Would appear my hope was short lived! Hmmm... what do you recommend now?
     

    Attached Files:

    Last edited: Dec 27, 2010
  14. FishFish101

    FishFish101 Private E-2

    Never mind, the windows defender has come back at the bottom right. identical to how it was before.
    Just took a couple minutes to load up. And to confirm, the Antivir pop ups are continually clocking the TR/Crypt trojan.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not helpful. I need to see exactly what files or registry keys are being found. Names of infections are really not that helpful.

    Next time just capture the popup and not your whole Desktop. ;)

    The log you attached from Avira was totally clean. Do you have a new log that is showing something?

    You need to run ComboFix as I suggested earlier and then attach the log from ComboFix. If this means shutting down Avira then that is what you will need to do.

    Also do the below as a start on a possible fix.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. FishFish101

    FishFish101 Private E-2

    Ok think that's everything you asked for.
    I also put on the most recent avira scan. I didn't actually click full scan, but the file attached was at at the top of the list of the 'reports' tab.

    Hope this is all useful.

    Again, obviously, huge thanks in advance.
     

    Attached Files:

  17. FishFish101

    FishFish101 Private E-2

    Forgot to mention how it's working.

    erm... Everything is perfect lol. Antivir is not picking anything up, and the windows defender alert is gone.
    Laptop is running smoothly, no signs of any trouble anywhere. Exactly as it appeared last night when I thought everything was ok.

    Confused again :p
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more minor cleanup to do.

    First a question. What is this AF-HSS Toolbar I see installed? It was just installed on Dec 25th? Is that when your problems began? If you don't know what this is or did not knowingly install it then uninstall it now.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62586
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [ElkTBhTOiqUEWYN.exe] C:\Users\FURIOU~1\AppData\Local\Temp\ElkTBhTOiqUEWYN.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)

    After clicking Fix, exit HJT.




    Now run avenger.exe by right clicking on it and selecting Run As Administrator
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Users\Furious Fred!\AppData\Local\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. FishFish101

    FishFish101 Private E-2

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKCU\..\Run: [ElkTBhTOiqUEWYN.exe] C:\Users\FURIOU~1\AppData\Local\Temp\ElkTBhTOiqUEWYN.exe

    These 2 files aren't in the list. I haven't done anything yet, just noted them down for you to see.

    Thank you.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just ignore anything that is missing and continue.
     
  21. FishFish101

    FishFish101 Private E-2

    Done everything you asked.

    (was a little hazy on deleting files manually from:
    C:\WINDOWS\TEMP
    C:\Users\Furious Fred!\AppData\Local\Temp

    Some files wouldn't remove. But I deleted nothing from today.

    Laptop seems to be running smoothly. Upon reboots, nothing detected by Antivir or Windows defender. Nothing else seems to be happening, running perfectly.

    I've attached the logs.

    Again, I'm sure a person of your ability and kindness hears this a lot, but- Thank you!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs from MGtools did not get fully updated so I cannot verify if everything was fixed. Please delete the current C:\MGlogs.zip file and then again run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file. Make sure you let it finish running.
     
  23. FishFish101

    FishFish101 Private E-2

    Hopefully that worked this time.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was better. ;) Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  25. FishFish101

    FishFish101 Private E-2

    Just one tiny thing, I couldn't find that MGclean.bat file so I left MGtools there. I don't really mind that much, it's a tiny file and I won't be using it ever again (hopefully)

    I am incredibly grateful. Thank you very much... How do I donate to majorgeeks? It's the least I can do.

    Thank you very much I really do appreciate the time and effort provided, fantastic service.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah yes! I forgot you had a 3 yr old version. Just delete the C:\MGtools folder.

    You're welcome. See the links in my signature. Thanks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds