Stubborn Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by cszuccato, Jul 14, 2010.

  1. cszuccato

    cszuccato Private E-2

    Hi. So, I recently aquired a computer from a friend. He gave it to me because it was infected, and he twice took it to a shop to be fixed, and the virus kept coming back. He said if I could fix it, it was mine.
    The virus it had was Anti Malware Doctor. I have gotten rid of that, but my Avira keeps finding a Trojan - "TR/CryptZPack.gen". Each time I quarantine it, delete it, but Avira keeps finding it. This has happened numerous times.
    I followed the instructions in the Malware Removal Guide thread on this forum, and have attached the reports here. I will put the Superantispyware log with the next reply.
    Thank you in advance for any help, as I am quite frustrated from trying to get this PC running cleanly.
    Let me know if any more information is required.
     

    Attached Files:

  2. cszuccato

    cszuccato Private E-2

    Ok, here is the log from Superantispyware.
    Thanks again for the help.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me the full path to the file that Avira is reporting on. In the mean time>

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    ghtvxear
    kuywqred
    mhfjzmxq
    
    File::
    c:\windows\system32\drivers\mhfjzmxq.sys
    c:\windows\system32\drivers\kuywqred.sys
    c:\windows\system32\drivers\ghtvxear.sys
    
    Folder::
    C:\Documents and Settings\user\Application Data\mjusbsp
    C:\Documents and Settings\user\Local Settings\Application Data\tjnet
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. cszuccato

    cszuccato Private E-2

    Hi TimW, thanks for replying so quickly.

    Ok, first, the information from Avira:

    From the scan result window;
    Object: wkhgvphw.sys
    Detection: TR\CryptZPACK.Gen

    From the Quarantine folder;
    Type: File
    Detection: Is the TR\Crypt.ZPACK.Gen Trojan
    Source: C:\Windows\system32\drivers\wkhgvphw.sys

    I will also attach the two log files you requested.

    Looking forward to finally beating this thing!

    Thanks, Chris
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hopefully, one last time.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\drivers\wkhgvphw.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wkhgvphw]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. cszuccato

    cszuccato Private E-2

    Ok, so I ran combofix and MGtools as requested, and have attached the logs for you. Since you also asked how things were running, I decided to run a scan with Avira. Well, it picked up four items. Here is the info...

    From the scan log, under Detections, Objects;
    d5153a5a79243ce61ad961aa9c41c2f6.szcpf
    A0003052.sys
    _wkhgvphw_.sys.zip
    wkhgvphw.sys.vir

    All four had the following under Detection;
    TR/CryptZPACK.Gen


    From the Quarantine folder;
    All four had the following under Detection;
    Is the TR/Crypt.ZPACK.Gen Trojan

    Under Source;
    C:\System Volume Information\_restore{F02A0B69-6C7D-4ACD-9B3B-66DC5470AF0E}-RP8\A0003052.sys
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\wkhgvphw.sys.vir
    C:\WINDOWS\system32\drivers\d5153a5a79243ce61ad961aa9C41c2f6.xzcpf
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_wkhgvphw_.sys.zip

    I then re-booted and ran another Avira scan. This one came up with ZERO detections! I hope this means we got it???

    Let me know how to proceed, and thanks once again.

    Chris
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  8. cszuccato

    cszuccato Private E-2

    Well Tim, you have my sincere gratitude.
    This was me before: :cry
    This is me now: :-D
    After following all the final steps, I ran Avira, and all the other programs I have, and they ALL came back with ZERO detections.
    I have set up this machine as per all the instructions, and I will now proceed to do the same with my older computer (don't worry, that one is clean, but I need to make alot of changes).

    Thank you once again.

    Cheers, Chris
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds