Unable to remove Trojan Crypt/XPACK/Gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by melm, Dec 15, 2009.

  1. melm

    melm Private First Class

    Avira picked up the Trojan Crypt/XPACK/Gen. I attempted removal, which Avira completed. However, it reappeared on the scan the next day.

    I have followed the "Read & RUN ME FIRST". Also, the Vista cleaning procedure.
    I was unable to obtain the combofix as it is unavailable at this time.
    The link to MGTools was not working and I could not find it on MG.
    I have MBAM and SAS on my computer, as well as Spybot, a-squared free trial,
    SpySweeper, IObit Security 360, Comodo, and until recently Trend Micro.

    I have attached the SAS, MBAM, and RootRepeal logs. Since I do not have the
    combofix or MGTools, I attached the Avira log for reference.

    Your help is greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). It should be downloaded to C:\MGTools.exe. You may need to disable Comodo before you run it.

    The link to ComboFix is back up. Download it but do not run it yet.

    Tell me what issues you have with running the MGTools.exe ...if you have any. Otherwise please attach the C:\MGLogs.zip.

    In the meantime, download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach the C:\Avenger.txt along with the C:\MGLogs.zip
     
  3. melm

    melm Private First Class

    Tim,

    Thank you for responding to my problem. I appreciate your help very much.

    I am sorry to say that I cannot get the ComboFix. The link still says that it is unavailable at this time. I have performed the other two tasks and have attached the logs.

    I have found the same Trojan on my other laptop, which runs XP Pro. I restored the laptop to the "out-of-box" state by doing a full recovery. Then I downloaded Mozilla Firefox from the website. I reinstalled SpySweeper from a disk. I downloaded MBAM, SAS, AVIRA, CCleaner, Defraggler, HiJackThis, Spybot Search and Destroy, a-Squared Anti-Malware, 7-zip File Manager, and QuickTime from MajorGeeks site or directly from the author's site, by going through MajorGeeks. I installed the new version of Java after removing the old. I installed IE8 from Microsoft directly. I scanned between all this and absolutely did not surf the web, or go to any other sites. (I did download some add-on helpers to Firefox, through them).

    I am not trying to combine this XP problem with the present one. I just wanted you to know that this occurred on a completely restored computer without going to any other sites. I can only deduce that the infections are in a program that I downloaded. Would that be a safe assumption? (I attached an online scan of the Vista system in case you wanted to see it at some point).

    Again, thank you for your help and your time.

    Melissa
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are confusing things by attaching logs from two different computers. Each should be addressed in their own threads. However, your Vista machine is clean. And the Avira log from the xp machine is complaining about the ASK Toolbar. I would suggest you remove it. It also indicates that the file was moved.

    Are you having any other issues??
     
  5. melm

    melm Private First Class

    I apologize for the confusion. I was just trying to make the point that this Trojan reappears after I completed all the steps. My Vista program mimics this. It appears to be clean, with the "C:\WINDOWS\System32\SsiEfr.exe" file locked. Then the Trojan will reappear on the Avira virus scan. Then a-squared will pick it up. After deleting and cleaning, toggling the system restore, it will come back.

    I intended to post my XP issue separately, once I have completed all the steps.

    Once the Trojan reappears on the Vista, do I start a new thread or reply to this thread?

    Thanks, Melissa
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Keep the vista issues in this thread. If it does reappear, you will need to run all the tools again and attach the logs.
     
  7. melm

    melm Private First Class

    Thank you Tim. I really appreciate your help.

    Can you tell me why the file SsiEfr.exe file is locked?

    Melissa
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That file belongs to SpySweeper.....a program that is questionable at best. You would be much better off keeping both SAS and MBAM. As per these final clean up instructions;

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Dec 21, 2009
  9. melm

    melm Private First Class

    Thank you for your response.

    What anti-virus, spyware, and anti-malware do you recommend?

    I have followed the computer maintenance and "How to Protect yourself from
    Malware".

    I have been using Trend Micro Internet Security. This problem only occurred when I tried out Avira. It kept telling me that the wrLZMA.dll and SsiEfr.dll files were contaminated or locked.

    I would really appreciate your recommendation for software to use, as I will be buying or renewing shortly after Christmas.

    Melissa
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We do not recommend that you purchase anything!! Often the "Security Suites" from different companies are worse than the freeware programs as far as using up system resources. I would just follow what is suggested in the "How to Protect Yourself......" thread and if you want to follow up with additional advice, post in the software forum where all can give personal opinions and suggestions. :)
     
  11. melm

    melm Private First Class

    Thank you for your help.
    I appreciate the time you've spent helping me out with this.
    Have a happy holiday season.

    Melissa
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome Melissa.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds