Crypt.XPack.Gen and other stuff

Discussion in 'Malware Help (A Specialist Will Reply)' started by jakeyj, Apr 14, 2011.

  1. jakeyj

    jakeyj Private E-2

    Hi, I've gone through the complete malware clean up process and all programs seemed to work. Afterwards I can no longer connect to the internet via Mozilla Firefox and I can only use IE. I thought I would just reinstall Firefox since it looked like I managed to get rid of the malware but I just got a pop up from Antivir so I'm going to attach my logs and see if anyone is able to help me.

    Thanks in advance for any help you can provide. I'm close to throwing my machine through the window :cry
     

    Attached Files:

  2. jakeyj

    jakeyj Private E-2

    Here is my other log

    Thanks again for any help you can provide.
     

    Attached Files:

  3. jakeyj

    jakeyj Private E-2

    Here is my antivir scan log.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    ComboFix shows that you have multiple anti-virus applications installed:
    You were advised against this in Step 2: Uninstalling Multiple Protection Applications of the R & R ME FIRST guide. *You need to uninstall all but one of them immediately.

    And you need to attach the requested C:\MGlogs.zip file to your next reply.
     
  5. jakeyj

    jakeyj Private E-2

    Thanks for you help. I'm sorry about having multiple AV installed. I have uninstalled all of them and instead installed AVAST on a suggestion from a friend. When I ran a scan with avast it didn't pick up any infected files but instead said: Error: file is offline - it is currently unavailable. (420006). It is a temp internet file so I am still concerned that I might have a problem.

    As you can probably tell I'm a bit of a noob when it comes to this so I appreciate any help and I hope that I did the right thing. :-o Since I have made an error with having multiple antivirus programs running should I go back through the removal steps?

    Furthermore, I can't seem to turn on the automatic updates for windows. :(

    I won't do anything else until I hear from you. Thanks again.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. No - there's no need to redo the steps. I'll now review your logs and will post instructions as needed. (including possible Windows automatic update solutions)

    dr.m
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, jakeyj

    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\User-1\desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *You are very low in available RAM and should definitely trim your startup processes with a tool such as Startup CPL 2.8.
    Also your available hard drive free space is getting dangerous low:
    *Question: What can you tell me about this file?
    C:\Documents and Settings\User-1\Application Data\CC5D.E4C

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Now install the latest Sun Java Runtime Environment

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  8. jakeyj

    jakeyj Private E-2

    Thanks for all the advice. It has taken me a little while to complete all the steps. I will try to address the steps you said I should undertake.

    You are very low in available RAM and should definitely trim your startup processes with a tool such as Startup CPL 2.8.I did this and turned off a few processes. How can I tell how much RAM I have available? I also cleaned up some space in the hard drive.

    *Question: What can you tell me about this file?
    C:\Documents and Settings\User-1\Application Data\CC5D.E4C

    I found the file and checked its properties and found the following:
    E4C File
    Opens with: Unknown application
    Size: 11.2 KB (11,488 bytes)
    Size on disk: 32.0 KB (32,768 bytes)
    Attributes: Archive

    I don't know what that means.

    Step 1 - I was successful in removing all the programs

    Step 2 - I ran combo fix and it told me that I still had AVIRA personal edition still running, but before I started any of this I removed the AV programs I had and AVIRA is not listed when I go to remove programs through the control panel so I'm not sure what's going on there.:confused Otherwise everything seemed like it went ok. I have attached the log.

    Step 3 -Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day). I was unable to delete anything since either there wasn't anything in most of the folders, or the file was from the current day.

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner - Ok no problems.

    Step 5:
    Program downloaded and installed OK - I have attached the C:\MGlogs.zip file


    Furthermore I went to Microsoft's website and I followed the instructions for a 0x80070424 error and I was subsequently able to update Windows and I don't get the message about being unable to update. The website said there were corrupted files that needed to be fixed.

    Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"
    Things seem much better. Overall the computer is running faster. I am using IE and Google Chrome and I have removed Mozilla. I installed a new version of Spybot, my version had some errors on it. When I ran it, it found a cookie tracker called "Double Click" associated with Google Chrome. I fixed the problem and it seemed ok. Now I don't know if that is a big deal or not and now I'm not sure if I should continue to use Google Chrome.

    Furthermore I am running Avast as AV program and I have installed Outpost Firewall. So I hope this should help.

    I'll wait for you to let me know how to proceed. Again I truly appreciate all the guidance.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, jakeyj

    Step 1:
    Please go to VirusTotal.com and upload the following file for analysis.
    c:\windows\system32\userinit.exe

    Then post the URL link to the file scan report.

    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :file
      userinit.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • SystemLook.txt
    • URL link to the VirusTotal scan results

    dr.m
     
  10. jakeyj

    jakeyj Private E-2

    Hi dr. m.,

    Step 1

    http://www.virustotal.com/file-scan...b8004733a4281395ad6723e0cf43d5f53f-1303142211

    Step 2

    I had a problem with combofix. When it restarted my machine, the AV started again and caused some problems. Then combofix stalled and I couldn't proceed with it and as a result no log was produced. I didn't redo it, because I wasn't sure if I should. Sorry :confused

    Step 3
    Attached

    Step 4
    Done

    Step 5 Attached

    As always, I thank you so much for you help and I look forward to hearing from you when you get a chance.
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hey, jakeyj

    re:Windows XP Malware Removal/Cleaning Procedure
    Please uninstall Outpost Firewall as directed in the above, then re-run my Step 2: instructions.

    Now attach the new C:\combofix.txt file to your next reply.

    * I'm seeking advice on the uninit.exe file that ComboFix reported as infected...


    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  12. jakeyj

    jakeyj Private E-2

    Hi dr. m,

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"


    Combofix worked fine this time. Sorry for my mistake previously. Once it was complete I reinstalled the firewall and restarted Avast.

    My system does seem better, however I get intermittent shutdowns of folders by Explorer (usually when I am using Windows Media Player) and the last couple of times using Internet Explorer it has been slow and stalled. However, I don’t know whether or not this is caused by malware. I’m still not sure which browser I should use or whether it matters.

    The log is attached. I look forward to your response when you can. Thanks as always.
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Please uninstall Online Armor's Firewall and do NOT re-install it until instructed, as we will still need to use ComboFix. *This means limiting use of your pc to ONLY check for replies from this thread until we are finished here.

    Step 1:
    Now using ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Using SystemLook again-
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :file
      %systemroot%\userinit.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Step 3:
    Now we'll collect a copy of the file for me to examine:
    Please go to start > Run and paste in the following:
    A compressed file called collect.zip will be retrievable under C:\.

    Please attach these files to your next reply:
    • C:\collect.zip
    • updated SystemLook.txt
    • C:\combofix.txt

    dr.m

    *NOTE: I've edited the SystemLook inquiry.
     
    Last edited: Apr 20, 2011
  14. jakeyj

    jakeyj Private E-2

    Hi dr. m,

    I have uninstalled the firewall and I wont reinstall until you tell me.

    Everything seemed to work well. The logs you asked for are attached.

    I look forward to hearing from you.

    jake
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please run combofix again just by double clicking it (right click and run as admin if win 7 or vista user) then attach the C:\combofix.txt for Dr Moriarty.
     
  16. jakeyj

    jakeyj Private E-2

    Here is the log you have requested.

    Thanks for your help and I look forward to your response.

    Jake
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Sofar, ComboFix's detection of userinit.exe appears to be false. Let's run this last online scan:

    Using ESET's Online Scanner

    Please attach the ESETScan.txt to your next reply.

    *How is your machine running now?
    dr.m
     
  18. jakeyj

    jakeyj Private E-2

    Hi Dr,

    I couldn't download ESET thru Internet Explorer, it just kept going back to the start screen in the small pop up window, so I had to use Chrome. It worked that way, I hope that is ok.

    Attached is the log, it found a worm, but said it quarantined it.

    I haven't really used my pc much since you told me to uninstall the firewall, but it does seem to be working ok for what little I've done. Do you have a tentative prognosis or is there a lot more cleaning to do?

    As always thank you so much for your help and expertise, I look forward to your response.

    Jake
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    We've finished with the cleaning, jakeyj. It is time to do our final steps- then re-install your firewall:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    You're welcome & "Safe surfing!" http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  20. jakeyj

    jakeyj Private E-2

    Thank you so much Dr. Moriarty,

    I don't mean to continue to bother you and I'm sure that you have other ppl that require help but I was wondering if you could tell me in layman's terms what was wrong with my pc? Was it the initial Crypt.XPack or was it the worm the ESET found? Or something else? And what was the problem with the file that Combofix found?

    If you don't have time to respond I understand and I will be happy :-D with the results but I am curious.

    The work that you do here is wonderful. I truly appreciate it.

    Jake
     
  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Having received my training from volunteer malware experts and encouraged to "Pay it forward", I'm happy to be able to assist you cleaning your machine, jakeyj.

    The malware scanners detected and removed traces of rogue security programs that pretends to be legitimate antivirus software and attempts to deceive unsuspecting PC users into paying to remove fake or simulated malware infections. A Trojan.Downloader was also removed. ComboFix also identified a problem with an important system, but that was a false detection.

    The C:\MGtools\Process.exe Win32/PrcView application was a false detection by ESET - process.exe is just a simple command line based Task Manager tool.

    dr.m
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    jakeyj

    If you don't mind, I would like to try SystemLook with a different SL script:
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :file
      userinit.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.

    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  23. jakeyj

    jakeyj Private E-2

    Hi Dr M.,

    I thought things were all clean. I just found out you posted again. Here is the log you asked for.

    Jake
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try again with the proper command for SystemLook ;)

    :filefind
    userinit.exe
     
  25. jakeyj

    jakeyj Private E-2

    Ok, here you go :)
     

    Attached Files:

  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    jakeyj

    All is well --- your files are the correct ones for your OS' service pack level.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds