Catchme.sys and TR/CryptXPACK.GEN

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mojohammer, Mar 16, 2011.

  1. Mojohammer

    Mojohammer Private E-2

    Two issues. I was in the process of seeking to remove TR/CRYPTXPACK.GEN and was running GMER when I came across the fact that I had Catchme.sys on my system. I ran RegSearch with "Catchme" as the search phrase and came up with the following text file. Could someone help me removing Catchme files?

    I may come back and ask for help on the TR/CryptXPACK.GEN. Avira keeps pulling it up a lot of files with the tag. It is being a bear to remove. Have used SuperAntispyware, Combofix, and Malwarebyte with no luck. Went in and did some manual removal of registry files. Hopefully, that will work. Will post logs if needed.


    -- Added Hijackthis log
    Thanks
     

    Attached Files:

    Last edited: Mar 16, 2011
  2. Mojohammer

    Mojohammer Private E-2

    Here is the hijackthis log
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    Catchme.sys is not malware - GMER which is also used by ComboFix use it as part of the rootkit detection software.

    If you wish me to check your machine for malware, please attach the requested scan logs from running the below:

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. Mojohammer

    Mojohammer Private E-2

    Thanks for the clarification. I must have misread the info in another post where catchme.sys was differeniated from catchme.exe. No matters

    Attached are logs from cmbofix and rootrepeal. Was in the process of creating those per the below link when you had responded.

    Am missing my SuperAntiSpyware log...need to find it

    To do
    - Log from MalwareByte
    - Log from MGTools
     

    Attached Files:

    Last edited: Mar 17, 2011
  5. Mojohammer

    Mojohammer Private E-2

    Adding MBWare and MGTools Logs
     

    Attached Files:

    Last edited: Mar 17, 2011
  6. Mojohammer

    Mojohammer Private E-2

    SuperAntispyware log
     

    Attached Files:

  7. Mojohammer

    Mojohammer Private E-2

    Was reading in a separate post where it was suggested to turn off system restore. I did this and now Avira does not picking up the TR/CryptXPACK.GEN now. False reporting?

    If you could look at my logs and tell me if you see anything else.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Please re-name "Cmbxit.exe" to ComboFix and move it directly to your desktop as instructed... NOT here:
    **You didn't attach the C:\MGlogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds