TR/Crypt.ZPACK.Gen Trojan reappearing in avira

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hachiko, May 31, 2010.

  1. Hachiko

    Hachiko Private E-2

    Hello, yesterday my antivirus Avira gave me pop ups of files being infected with TR/Crypt.ZPACK.Gen Trojan and so I quarantined them and then did a full scan. I thought the scan took care of the trojan because I rebooted and I no longer had pop ups. Later, I rebooted again and got more pop ups about more files being infected.

    So I followed the instructions for the READ & RUN ME guide except for the "Empty ALL Quarantine type folders" part. I looked into what I quarantined in Avira and there are about 160 files in there and most located in the C:\WINDOWS\system32\drivers directory. So I'm scared to delete these since they sound important.

    Attached are the logs from the scans. Is my computer clean now or not because I did not delete the quarantine folder?

    Sorry if I did something wrong here. I thought I read all the stickies before posting.
     

    Attached Files:

  2. Hachiko

    Hachiko Private E-2

    SAS log and a small screen shot of some quarantined files.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not much to clean up, so let's just have you do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    Driver::
    fzfodt
    File::
    c:\windows\system32\drivers\fzfodt.sys
    c:\windows\Owizetunuxafujah.dat
    c:\windows\Evirivoqulic.bin
    c:\documents and settings\Changpen\Application Data\vqdlkr.dat
    c:\documents and settings\LocalService\Application Data\vqdlkr.dat
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. Hachiko

    Hachiko Private E-2

    Thank you for helping me! I have Windows XP by the way, home edition, 32 bit.

    I accidentally ran the MGtools.exe first because I was confused. Then I ran C:\MGtools\analyse.exe and accidentally left a windows explorer window opened when I pressed Fix. I feel like a klutz.

    I ran ComboFix from the desk top but after reboot msn messenger loads automatically and my antivirus turned itself back on.

    Is there an ad blocker that you suggest for Google Chrome? I was using Chrome while the pop ups occured and I have no ad blocker on it and feel that this may have caused the infection. I am now using and may revert back to Firefox with Adblock

    I have had no pop ups of any files being infected. I ran another full system scan in Avira before doing the scans you told me to do and there were 13 files and most located in C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}

    I'm just scared to do internet banking now
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to ask about ad-blocking in Chrome in the software forum.

    If you are concerned about your online banking, I suggest that you use a different computer and change your password (s). I have not seen anything that might suggest you are compromised, but being safe is better than being sorry.

    Do you know why your DNS server settings are:
    DNS Servers . . . . . . . . . . . : 8.8.8.8
    8.8.4.4

    Instead of being set to obtain DNS automatically?

    As to what is being found by Avira, all the items in your system restore folder can not be removed until you toggle system restore.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  6. Hachiko

    Hachiko Private E-2

    DNS-- There was an incident where my default DNS seemed to have died. The browsers would not load any pages but instant messaging clients would still work. And I remembered that most of the times when you set it to obtain DNS automatically, it's just the ISP's DNS and Google's DNS sounded better than Mediacom's DNS at the time. Maybe I wasn't paying enough attention in class..

    Thank you for your help. I have followed those steps but I don't have HijackThis in my add/remove programs to remove.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. Let me know if you have any other malware issues. Otherwise, you are most welcome and safe surfing.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds