TR/CRYPT XPack Gen and or ADSPY/adspy.gen3

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by plants99, Jun 6, 2011.

  1. plants99

    plants99 Private E-2

    Hi, I am somewhat concerned that i am not following procedure correctly and if that is the case i apologise in advance. I have read and re read and followed all instructions on your pages so here goes!
    The problem is that i have a 2 yr old Dell Dimension with XP (32 bit) and 3 monitors( for my work). I have AVIRA and SPYBOT and several others ( some now removed) and have a daily regualr scan. I use an AOL mail account and Firefox browser (but also IE ). About 4 days ago I began getting warning tones from the PC and then a AVIRA detection notice panel showing the TR/CRYPT XPACK Gen and ADSPY Gen3 virus/trojan warning. Whatever option( delete/repair/deny access etc) i chose was ineffective. Some days ago i received 'mailer daemon' warning of returned emails. Basically my AOL address book was used to send hundreds of malicious emails last night ( Chinese script and email addresses) and about 4 on Friday last then more on Saturday then scores/100's last night.
    I started on your site after an abortive attempt to turn off system restore and run AVIRA in Safe mode- result ..nothing and i have lost all previous SR dates!
    So back to your excellent site and now following the guidelines i have run all the diagnostics/tools/antivirus progs suggested and now AVIRA can't pick it up...in fact not one of the logs has a positive result. Where from here? Any help would be very much appreciated as i am out of my depth (as you can probably tell!)
     

    Attached Files:

  2. plants99

    plants99 Private E-2

    MG Log Zip
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  4. plants99

    plants99 Private E-2

    Sorry did not send the Malware Bytes BAM Log
     

    Attached Files:

  5. plants99

    plants99 Private E-2

    Thanks for a really quick response....TDSS Killer run (with no hidden files/all files showing) as per suggestion. log attached but no threat found.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs. Could you attach the C:\Documents and Settings\France\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2011-06-03 (13-57-03).txt please?

    So you say Avira is no longer detecting threats? If it IS then you need to give me exact files and their locations.
     
  7. plants99

    plants99 Private E-2

    Hi, Avira picked up on it last night during the daily scan. The report warning is as follows:
    The file 'C:\Documents and Settings\France\Desktop\ComboFix.exe'
    contained a virus or unwanted program 'TR/Crypt.XPACK.Gen' [trojan]
    Action(s) taken:
    The file was moved to '4e5acb83.qua'!

    Scan ended [The scan has been done completely.].
    Number of files: 291138
    Number of folders: 11559
    Number of malware: 1
    Number of errors: 3

    It appears to be in the Combo fix file. Here attached is the txt file from MBytes full scan from yesterday.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's a false positive on Aviras part! :) Combofix is obviously not malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. plants99

    plants99 Private E-2

    OK, Thanks for the steps which i will follow BUT first -i followed your procedures yesterday to the absolute letter but today the COMBOFIX icon is no longer on the desktop and the run command also says it cant find it. This is the second time it has disappeared (and yesterday was the second time i downloaded it). What is going on? Is this sinister and why shoul;d it just vanish but the logs from yesterday ( and the previous time) are still there. A simple file search for combo reveals only a text file 'quarantined files' ( attached) but yet the result of the combo fix was no detection.
    Shall i skip the combofix uninstall and carry on as per your instructions?
     

    Attached Files:

  10. plants99

    plants99 Private E-2

    Sorry Kestral 13, but i think that the problem still exists as my AOL a/c has sent at least 6 malicious emails earlier today.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But no malware exists on your machine. If it's emails being sent out from your account and you did not send them then this is something you can ask about in the software forum. If avira detects anything OTHER than valid tools as being problems then you need to tell me what exactly.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You cannot find Combofix because Avira detected it as malware!!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try downloading a fresh version and run it. Attach the results for me to look at.
     
  14. plants99

    plants99 Private E-2

    Just wanted to thank Tim and all at Major Geeks for all your help. Am not sure what the status is of my system but will revert if i am struggling but have a lot of your 'fixes' to uninstall as per your instructions and will then reboot and keep fingers crossed ( & of course buy some decent spyware protection as prescribed) ......there is no doubt i couldn't have got through this problem without you guy's so a big thank you!!!!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds