Spyware / Malware / Virus Removal
Infected with a Trojan [Closed]
10 min read
Matts1019
Topic Starter
I have Avira running and its found TR/Crypt.ZPACK.gen8. I need some help removing it before it gets bad. Ive caught it early as Im not seeing very many symptoms.
Ive uploaded dds.txt and attach.txt
Satchfan
Hello Matts1019 and welcome to the WTT forum.
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
I am looking at your logs now and will reply with instructions shortly.
Satchfan
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
I am looking at your logs now and will reply with instructions shortly.
Satchfan
Satchfan
Hello again
Run aswMBR
Run RogueKiller
Download RogueKiller to your desktop.
Please post the contents of the RKreport.txt in your next reply.
Please include the following in your next post :
aswMBR log
RKreport.txt
Thanks
Satchfan
Run aswMBR
- download aswMBR.exe to your desktop.
- double click aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
Run RogueKiller
Download RogueKiller to your desktop.
- close all running programs
- for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
- when the prescan is finished, click on Scan
- click on Report and copy/paste the content in your next post
- NOTE: DO NOT attempt to remove anything that the scan detects.
Please post the contents of the RKreport.txt in your next reply.
Please include the following in your next post :
aswMBR log
RKreport.txt
Thanks
Satchfan
Matts1019
Here it is. Sorry it took so long
RogueKiller V8.2.0 [10/22/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Matt [Admin rights]
Mode : Scan – Date : 10/27/2012 15:52:31
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HM321HI SATA Disk Device +++++
— User —
[MBR] a592a290244c08bb23751d11c3bcc33d
[BSP] 06dddc12108242472105b2f203595693 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 285912 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 585957376 | Size: 15069 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 616818688 | Size: 4063 Mo
User = LL1 … OK!
User = LL2 … OK!
+++++ PhysicalDrive1: SDHC Card +++++
— User —
[MBR] 83b42057fb3fd1d945874c9bf1406a5b
[BSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 8192 | Size: 3777 Mo
User = LL1 … OK!
Error reading LL2 MBR!
Finished : << RKreport[1].txt >>
RogueKiller V8.2.0 [10/22/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Matt [Admin rights]
Mode : Scan – Date : 10/27/2012 15:52:31
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HM321HI SATA Disk Device +++++
— User —
[MBR] a592a290244c08bb23751d11c3bcc33d
[BSP] 06dddc12108242472105b2f203595693 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 285912 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 585957376 | Size: 15069 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 616818688 | Size: 4063 Mo
User = LL1 … OK!
User = LL2 … OK!
+++++ PhysicalDrive1: SDHC Card +++++
— User —
[MBR] 83b42057fb3fd1d945874c9bf1406a5b
[BSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 8192 | Size: 3777 Mo
User = LL1 … OK!
Error reading LL2 MBR!
Finished : << RKreport[1].txt >>
Matts1019
aswMBR.exe
Satchfan
Thanks for the logs.
We'll have to run more to see what is causing this message from Avira because there was nothing bad in those logs.
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
Download and run OTL
OTL.txt
Extras.txt
AdwCleaner log
Thanks
Satchfan
We'll have to run more to see what is causing this message from Avira because there was nothing bad in those logs.
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
- run AdwCleaner and select Delete
- when it has finished it will ask to reboot - allow the reboot
- on reboot a log will be produced; please attach the content of the log to your next reply
Download and run OTL
- download OTL to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- click Scan all users.
- under Custom Scan paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
services.exe
/md5stop
%systemroot%\*. /rp /s
DRIVES
CREATERESTOREPOINT - click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- you may need two posts to fit them both in.
OTL.txt
Extras.txt
AdwCleaner log
Thanks
Satchfan
Matts1019
Its kind of wierd, I couldn't find the process random.exe.
Anyway…
# AdwCleaner v2.005 - Logfile created 10/28/2012 at 00:50:07
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Matt - MATTSLAPTOP
# Boot Mode : Normal
# Running from : C:\Users\Matt\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\user.js
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\uTorrentBar
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\Matt\AppData\Local\Babylon
Folder Deleted : C:\Users\Matt\AppData\Local\Conduit
Folder Deleted : C:\Users\Matt\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Matt\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Matt\AppData\LocalLow\uTorrentBar
Folder Deleted : C:\Users\Matt\AppData\Roaming\Babylon
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentBar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A97B89CD-B65C-49DD-AF46-2B772C627456}
Key Deleted : HKLM\Software\uTorrentBar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A97B89CD-B65C-49DD-AF46-2B772C627456}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{274F6EB0-2B0E-49AE-96B9-ECD034CECB98}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4B826204-90A2-442E-A0F8-1BC04BCC567E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[OK] Registry is clean.
-\\ Mozilla Firefox v15.0.1 (en-US)
Profile name : default
File : C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\bjurt7uh.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v22.0.1229.94
File : C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [4171 octets] - [28/10/2012 00:50:07]
########## EOF - C:\AdwCleaner[S1].txt - [4231 octets] ##########
Satchfan
. What do you mean?Its kind of wierd, I couldn't find the process random.exe
I'll wait for the other 2,(OTL), logs.
Matts1019
Well, when i looked for it at the task manager, I was told I would see random.exe under processes.
Satchfan
By whom?I was told I would see random.exe under processes.
Matts1019
OTL
Matts1019
My dad. He's quite adept at these sorts of things. Also, I read it on a thread by someone who had a similar problem. Isn't it true that it must fixed by manually removing the virus?
Also, another strange thing, Avira ran another scan and so far there are 11 warnings but no virus detected.
Satchfan
I did ask for you not to follow any other instructions while we are fixing this.
Many sites suggest fixes and you'll also find that the general advice is to look for a "randomly-named" file, (not a file named random.exe).
This is very outdated advice as malware has come a long way since then.
The vast majority of infections now mask themselves as genuine Windows files which is why it is dangerous to follow the advice of anyone who is not trained in their detection and removal.
I think that we are probably nearly clear but until I have checked you latest logs, please do not attempt any more self-help.
Satchfan
Many sites suggest fixes and you'll also find that the general advice is to look for a "randomly-named" file, (not a file named random.exe).
This is very outdated advice as malware has come a long way since then.
The vast majority of infections now mask themselves as genuine Windows files which is why it is dangerous to follow the advice of anyone who is not trained in their detection and removal.
No. The alert by Avira is given for more than one type of infection and they need to be individually identified and dealt with acccording to the type it isIsn't it true that it must fixed by manually removing the virus?
I think that we are probably nearly clear but until I have checked you latest logs, please do not attempt any more self-help.
Satchfan
Matts1019
That's good news. Although, I didn't follow any other instructions. As you can see I didn't even understand them.
Just thought I'd bring it up…
Carry on Chief.
Satchfan
I didn't follow any other instructions. As you can see I didn't even understand them.
Well that looks pretty good apart from a few entries which we’ll fix.
Run OTL
- double click on the icon to run it.
- copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{5687FEC6-A477-45EE-932D-C1D663450DEA}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKLM\..\SearchScopes\{5687FEC6-A477-45EE-932D-C1D663450DEA}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKCU\..\SearchScopes\{5687FEC6-A477-45EE-932D-C1D663450DEA}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} [2012/01/21 14:18:41 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} :Commands [purity] [emptytemp] [Reboot]
- click the Run Fix button at the top
- let the program run unhindered, reboot when it is done
- please post the OTL fix log
Download Malwarebytes-Anti-Malware
Click here.
- double-click mbam-setup.exe and follow the prompts to install the program.
- at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
- if an update is found, it will download and install the latest version.
- once the program has loaded, select Perform quick scan, then click Scan.
- when the scan is complete, click OK, then Show Results to view the results.
- be sure that everything is checked, and click Remove Selected.
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
Logs to include in the next post:
OTL fix log
Mbam.txt
Can you tell me if there are any outstanding problems.
Satchfan
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI