win32 Heur tr/crypt.xpack now bsod

Discussion in 'Malware Help (A Specialist Will Reply)' started by Petered, Dec 31, 2009.

  1. Petered

    Petered Private E-2

    I opened an infected file, first I knew was win32 Heur notification.

    Then I kept getting fake virus checker asking me to download stuff,; which I did not do.

    Also kept getting TR/crypt.xpack.gen

    Was running AVG, Zone Alarm & Ad-Aware

    Installed Antivir & Malwarebytes Anti-Malware after removing AVG & shutting down AdAware. This removed a load of stuff, attached are log files.

    Now getting BSOD with messagepage fault in non paged area STOP

    0x00000050(0xADB89000,0X00000000,0X8059DCFD,0X00000000)

    PC will start in safe mode, don't know what to do next; please help!!

    I've run Malwarebytes Anti-Malware in safe mode with no infections showing.

    I've been struggling with this all Christmas & do not seem to be getting anywhere.

    Thanks
     

    Attached Files:

  2. Petered

    Petered Private E-2

    Original Malwarebytes log attached showing all the bad stuff removed.

    P
     

    Attached Files:

  3. Petered

    Petered Private E-2

    Combofix log attached; please could you advise on what to delete.

    Thanks
     

    Attached Files:

  4. Petered

    Petered Private E-2

    Now got Avira reporting trojan TR/Agent.AE.72.

    This is first time I have seen this.
     
  5. Petered

    Petered Private E-2

    Now got mulitple instances of Backdoor.Bot being reported by Avira.

    Please Help!!!!
     
  6. Petered

    Petered Private E-2

    Found & removed Trojans msbsvo32.exe & srde64.exe.

    Removed also from registry key.

    Fingers crossed!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Each time you posted, it put you back to the end of the line.

    You appear to have two FW installed according to the Combo log:
    FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

    If so, uninstall one!

    You can use windows explorer to find and remove:
    c:\windows\system32\REN3C.tmp
    c:\windows\system32\REN3B.tmp

    Now, I don't know where you stand as far as the infection. The two items you say were found and removed are part of it. But you need to now attach a new MGLogs.zip as well as a new ComboFix log.
     
  8. Petered

    Petered Private E-2

    PC came from Dell with Mc Afee installed but does not show on Add or Remove programs, so not sure how to uninstall it.

    Files below have been deleted:
    c:\windows\system32\REN3C.tmp
    c:\windows\system32\REN3B.tmp
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can't see what to do without those logs. It is possible it is just a left over that Combo is picking up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds