I have a virus of unknown origin and im not able to figure out what it actually is. First my AntiVir detected and deleted 3 trojans
TR/Crypt.XPACK.Gen [Trojan] C:\Document and Settings\HP_Administrator\Local\Settings\Temp\vistasp1.exe
TR\Rootkit.Gen [Trojan] C:\Windows\system32\drivers\clbdriver.sys
TR/Crypt.XPACK.Gen [Trojan] C:Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5X8FPKE4\Scan[1].exe
after it was deleted my desktop dissapeared my task manager was disabled and im getting advertisments from PCPrivacyCleaner. While not being able to acess any programs
Im trying to post the hijackthis log but the fourm says its out of date there is no way for me to update it as my comp is paralyzed the version im using is v2.0.2 so i dont get it somone plz help
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders." Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download Malwarebytes' Anti-Malware to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Now see if you can also post the hjt log
Also "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:00: VIRUS ALERT!, on 7/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Finally able to access IE on the infected comp i have the hijackthis set on start up. I have Malwarebytes Anti-Maleware i tried to run it but the virus is stopping all anti software from completing the scans. ATM when my windows starts up my desktop is disabled and the icons disappear my task manager and all administrator access' are disabled i cannot acess control panel. The same happens when i boot into safe mode.
If sdfix.exe won't run, rename it to sdfix.com.
I've seen malware disable .exe from running. DON'T rename any windows files, just the tools I have you use.