Trj.Pupack.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by gingerninja, Dec 29, 2010.

  1. gingerninja

    gingerninja Private E-2

    Hi,

    My Antivirus scan discovered a virus and Adware today. As I understand it the virus has something to do with Zcodec.exe (which I have no recollection of ever downloading). The issues were not fixed by the AV software (Panda Internet Security 2010) but simply notified me.

    Issues found and there locations are:

    Adware detected: Adware/SecurityError

    Path: D:\System Volume Information\_restore{20FF2C5B-CC4A-48BA-90F3-78E9C017630D}\RP178\A0039673.exe[²ÜÇ\Loader.dll]

    Virus detected: Trj/Pupack.A

    Path: D:\System Volume Information\_restore{20FF2C5B-CC4A-48BA-90F3-78E9C017630D}\RP178\A0039673.exe[zcodec.exe]


    I ran through the Read & Run Me First and hoped that that would fix the problem. Neither SAS nor Malwarebytes found anything wrong.

    I've attached the logs in the hope that you can check if there are any issues within them.

    I did run a second Panda scan after the process and the issues were still there.

    The virus & adware are found in the "System Volume Information" folder of a partition that isn't the system partition. Could this be stopping the antivirus from removing them? I have tried to get info on the files in question but I'm not allowed to open the folder.

    I've heard of ways to access the "System Volume Information" folder but I'm not sure if accessing and deleting files from it is either a good idea or a means of removing the virus successfully.

    Some advice and/or help would be massively appreciated.

    Thanks

    GingerNinja
     

    Attached Files:

  2. gingerninja

    gingerninja Private E-2

    The MGtools Log

    Thanks
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Items found in your system volume folders can only be removed by toggling system restore. If that is all that is being found, then you just need to toggle system restore to remove them. ;)

    Refer to the cleaning procedures pointed to by step 7 of the READ ME
    for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    Then reboot and Enable System Restore to create a new clean Restore Point.
     
  4. gingerninja

    gingerninja Private E-2

    Simple as that?

    Nice one.

    Thanks for such an incredibly quick response too.

    Cheers TimW

    :)
     
  5. gingerninja

    gingerninja Private E-2

    Just out of interest how would the virus have got into the system volume info folder?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    From an old infection that might have been removed previously by your AV software.

    And yes, that simple. You are most welcome. Your logs are clean so here are the clean up instructions:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  7. gingerninja

    gingerninja Private E-2

    Hi,

    Hope you're still there TimW.

    I toggled System Restore yet the antivirus is still picking up the 2 instances as before. I'm not sure how this is possible since when I go to the folder and right click to the properties it says that the folder is empty. What's going on?

    I've toggled system restore on all drives and also for the offending drive alone.

    Any ideas???

    Thanks
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you need to tell TimW the exact file and file path of what is being found. He will log in in a couple hours I expect.

    EDIT: I see you are saying that even after toggling system restore, stuff is still being detected in system restore. Just wait to see what Tim says.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is still detecting this? Is it Adaware? Please tell me the full path that is being detected. I am assuming that when you turned off system restore, you did reboot and then re-enabled it.
     
  10. gingerninja

    gingerninja Private E-2

    Thanks for getting back Tim,

    It's my Panda Internet Security Antivirus software that's picking this up. The full path of the files are listed in my first post above. I hope that's the info you need.

    Thanks again.

    Gingerninja :confused
     
  11. gingerninja

    gingerninja Private E-2

    Oh and yes, I did turn off system restore then reboot then turn on system restore.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is your D: drive? Is it a partition on your hard drive or is it a second hard drive?
     
  13. gingerninja

    gingerninja Private E-2

    My D: drive is a partition on my only drive. The OS is on the C: partition of the same drive.

    Thanks
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I wouldn't worry about it. You don't use the D: drive for doing any restore work and as long as the restore folder on your C: drive is clean, you don't need to worry with the restore folder on the D: drive. I don't even know why you have a restore folder on that drive.
     
  15. gingerninja

    gingerninja Private E-2

    Ok, thanks.

    I appreciate your time and efforts.

    Cheers

    Gingerninja :)
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds