Alot wrong, and Tp/crypt.ZPack.gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by DJPwnage, Apr 12, 2010.

  1. DJPwnage

    DJPwnage Private E-2

    The Root thing gave me a Fops DeviceIoControlError
    So i couldn't get a log from it.

    I have the Google Redirect Virus also, Tr/Crypt.Zpack.Gen Thing, suspect Adware, and i get a "Congratulation you've won" Sound byte thing every once and a while, with a invis Internet Explorer process, XKPrTTU.exe is my suspected file that is the virus, the problem is that every-time i delete it, it pops back up. Also a few of my programs add a Space in their name like. Utorrent .exe, Msn*w/e the rest its* .exe and so on. I can sometimes see them in my Task manger. Umm This all started about a week ago as i remember, but the Tr/Crypt.Zpack.Gen Virus could have been on for a while. No signs were seen till a week ago tho, i was not doing anything, i might have Defrag my Pc tho.

    That is all my info and the Logs asked for. My Pc specs if needed will be posted apon response.

    On a side note, i doubt its Malware but! When i am on a window and i click sometimes it will flicker*The window* and or switch to a different open window. Also when ever i open a drop menu *U know the ones where u click the little down arrow and it a drops with options Lol* i will flicker and close it and or just close it over and over. Sometimes it works perfectly without any problems but it happens alot still. This may be a windows 7 error, i have had it since about, 6-7 months ago. i think using my Windows 7 disc to see if i can repair anything might help but i wanted to do this first then try that if u guys cant find out what is wrong.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    RenV::
    c:\program files\Adobe\Reader 8.0\Reader\Reader_sl .exe
    c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt .exe
    c:\program files\ASRock Utility\InstantBoot\InstantBoot .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier .exe
    c:\program files\Common Files\Java\Java Update\jusched .exe
    c:\program files\DAEMON Tools Pro\DTProAgent .exe
    c:\program files\iTunes\iTunesHelper .exe
    c:\program files\Microsoft Office\Office12\GrooveMonitor .exe
    c:\program files\QuickTime\QTTask            .exe
    c:\program files\QuickTime\QTTask           .exe
    c:\program files\QuickTime\QTTask          .exe
    c:\program files\QuickTime\QTTask         .exe
    c:\program files\QuickTime\QTTask        .exe
    c:\program files\QuickTime\QTTask       .exe
    c:\program files\QuickTime\QTTask      .exe
    c:\program files\QuickTime\QTTask     .exe
    c:\program files\QuickTime\QTTask    .exe
    c:\program files\QuickTime\QTTask   .exe
    c:\program files\QuickTime\QTTask  .exe
    c:\program files\Realtek\Audio\HDA\RtHDVCpl .exe
    c:\program files\Yahoo!\Messenger\YahooMessenger .exe
    c:\program files\Zune\ZuneLauncher .exe
    c:\windows\WindowsMobile\wmdc .exe
    
    AtJob::
    
    File::
    c:\programdata\eX6RJ2.dat
    C:\Users\Keon\AppData\Local\olV3RohQ
    C:\Users\Keon\AppData\Roaming\Microsoft\Windows\Templates\olv3rohq
    C:\ProgramData\olV3RohQ
    C:\ProgramData\XKP4rTTU.exe
    C:\Windows\temp\fla8F98.tmp
    C:\Windows\temp\flaAD11.tmp
    C:\USERS\KEON\LOCALS~1\TEMP\420DC383.DAT
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Because of the infection, I want you to uninstall:
    Adobe\Reader 8.0
    Adobe\ARM
    DAEMON Tools Pro
    iTunes
    QuickTime
    Yahoo!\Messenger

    Run CCleaner, reboot and reinstall that software.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. DJPwnage

    DJPwnage Private E-2

    umm i guess its running good. Lol i have not done much so idk if anything big is different xD
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still more.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RenV::
    c:\program files\SUPERAntiSpyware\SUPERAntiSpyware .exe
    c:\program files\uTorrent\uTorrent .exe 
    
    File::
    C:\"Desktop Security 2010.lnk
    
    Folder::
    C:\Desktop Security 2010
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTimeResourcesQuickTime"=-
    "OrganizerMicrosoft"=-
    "annoannopQuickTime"=-
    "mstore10Clip"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now uninstall:
    SUPERAntiSpyware
    uTorrent

    Run CCLeaner and reboot. Re-install the software.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. DJPwnage

    DJPwnage Private E-2

    I don't know what happen to ComboFix, but it restarted my pc and then said something about Access Denied, wall*something might have been paper01.


    I am sorry i hope this didn't mess the help up.

    I figured redoing the CF would mess something up, but i did anyways hoping it wouldn't, i am taking the responsibility.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not to worry as your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. DJPwnage

    DJPwnage Private E-2

    Well i cant say for sure if i am clean, but i think i may have the Redirect virus, and i have not gotten a good number of the problems i have had before. I hope this got rid of them. I have Comodo and Avast install, Firewall for Comodo.
    The Tp/crypt.Zpack.gen is what i am really worried about. Idk how to know if its gone or not, but i will take your word it is. If there is any other test i can take to see if it is really gone or w/e please let me know, i know i am probably wasting your time but i am very good with computers and for me to ask others is a big thing.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. DJPwnage

    DJPwnage Private E-2

    Okay here is the Gmer thing.

    It was denied like System or something.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run step 6 in the READ & RUN ME to disable your Disk Emulation software. Then reboot. After reboot, you need to run GMER again and attach a new log.
     
  11. DJPwnage

    DJPwnage Private E-2

    Well i was told to pretty much put my stuff back to normal so i did.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now re-run GMER and attach that log to your next reply.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. DJPwnage

    DJPwnage Private E-2

    Umm that MGTools or w/e was suppose to be cleaned when u told me to..btw.

    Neways i got all the logs.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry, but ...what?

    You have a system file that is infected which we are trying to replace. So, let's try a different approach.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    TDL::
    C:\Windows\System32\drivers\atapi.sys
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  15. DJPwnage

    DJPwnage Private E-2

    in one of your post u told me to run the MG Cleaner thing XD nevermind xD.


    I ran the Combofix thing but got BSOD it restarted then had a problem with some files being weird and Comobo being invis and not able to shut it down so had to restart again, ad then realized my CD emu was on again XD, but fixed that. Neways i ran it and hope it got the right logs XD.

    Umm for some odd reason, Combofix didn't save a log...i re-ran it like i said, but it didn't make a log for the second time i ran it i guess. I looked at the ones i have and they are not dated the right date.


    wait..nevermind it was created in a Folder called ComboFix, its dated right...So i hope this is the right one.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try it again.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    RenV::
    c:\program files\Adobe\Reader 8.0\Reader\Reader_sl .exe
    c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt .exe
    c:\program files\ASRock Utility\InstantBoot\InstantBoot .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier .exe
    c:\program files\Common Files\Java\Java Update\jusched .exe
    c:\program files\DAEMON Tools Pro\DTProAgent .exe
    c:\program files\iTunes\iTunesHelper .exe
    c:\program files\Microsoft Office\Office12\GrooveMonitor .exe
    c:\program files\QuickTime\QTTask            .exe
    c:\program files\QuickTime\QTTask           .exe
    c:\program files\QuickTime\QTTask          .exe
    c:\program files\QuickTime\QTTask         .exe
    c:\program files\QuickTime\QTTask        .exe
    c:\program files\QuickTime\QTTask       .exe
    c:\program files\QuickTime\QTTask      .exe
    c:\program files\QuickTime\QTTask     .exe
    c:\program files\QuickTime\QTTask    .exe
    c:\program files\QuickTime\QTTask   .exe
    c:\program files\QuickTime\QTTask  .exe
    c:\program files\Realtek\Audio\HDA\RtHDVCpl .exe
    c:\program files\Yahoo!\Messenger\YahooMessenger .exe
    c:\program files\Zune\ZuneLauncher .exe
    c:\windows\WindowsMobile\wmdc .exe
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now re-run GMER.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * GMER log
    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. DJPwnage

    DJPwnage Private E-2

    Okay i am about to run it, But one thing. Most if not all of those programs are deleted already...i looked at the Program folder and almost if not all of those are not there. So..just wanted to let you know before i ran it, (dont want to mess anything up). Maybe the Combofix Log was faulted?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and run it and attach the new logs as requested, please.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds