TR/Crypt.XPACK.Gen - Avira Antivirus keeps detecting it.
Hi,
I noticed that while my Dell Vostro 1000 computer was sitting idle, my Avira Antivirus would, at random times, detect the TR/Crypt.XPACK.Gen trojan at C:\WINDOWS\system32\drivers\atapi.sys
Avira Antivirus would beep and put up a message for about 10 seconds. I finally caught the message and hit "delete" the problem, but the problem keeps coming back.
I did a full disk scan by Avira Antivirus. Found Nothing.
I did a full disk scan by AVG Antivirus. Found Nothing.
I did a full disk scan by Malwarebytes. Found Nothing.
I did a quick scan using Microsoft Security Essentials. Found Nothing.
I did a full disk scan by Lavasoft Adaware. It found the trojan, but in a different place. C:\System Volume Information\...\A0O21266.sys
But I can't find the directory C:\System Volume Information\ , even showing hidden system files.
Anyways, I told Lavasoft Adaware to delete it.
I left Lavasoft Adaware running on my computer for the afternoon, idle. No beeping messages of the Trojan found.
So I removed Lavasoft Adaware from my system, and brought back Avira Anti-virus. After a couple of hours of idling, the computer beeped. Avira Antivirus found the trojan again.
So I'm at my wit's end. I don't know what to do anymore.
That's why I am here.
If someone could help me, it would be greatly appreciated.
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 6:51:26 PM, on 7/17/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
Please proceed as follows :-
Step 1
We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Download Security Check by screen317 from
HERE or
HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Let me see logs from Combofix and Security Checks in your reply please.
3) The Spybot directions look too complicated, so I simply uninstalled it.
4) Didn't see directions for Spyware Blaster, so I uninstalled it.
5) I ran Combofix, but it found that Microsoft Security Essentials was running (I thought I had deleted it). So I uninstalled it, and continued running Combofix.
6) After Combofix finished, I logged in to get Security Check, and ran that (after closing FF and Zonealarm and Avira).
ComboFix 10-07-18.05 - Paul 07/19/2010 16:06:23.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1340 [GMT -4:00] Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
Results of screen317's Security Check version 0.99.4 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Avira AntiVir Personal - Free Antivirus ZoneAlarm ZoneAlarm Toolbar ZoneAlarm Spy Blocker Avira successfully updated! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware HijackThis 2.0.2 CCleaner Java(TM) 6 Update 18 Java(TM) 6 Update 20 Out of date Java installed! Adobe Flash Player 10.1.53.64 Adobe Reader 9.3.3 Mozilla Firefox (3.6.6) ```````````````````````````````` Process Check: objlist.exe by Laurent Avira Antivir avgnt.exe Avira Antivir avguard.exe ```````````````````````````````` DNS Vulnerability Check: Unknown. This method cannot test your vulnerability to DNS cache poisoning.
The windows firewall appeared to be enabled, this might have happened when you stopped Zonealarm. It wasn`t a problem, just be aware when Zonealarm is back in service; make sure windows Firewall is OFF.
Proceed as follows:
Step 1
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text inbetween the dooted lines below into it
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to ALLOW the changes.Instructions available HERE
Make sure you are connected to the Internet.
Double-click on mbam-setup.exe to install the application.
When the installation begins, follow the prompts and do not make any changes to default settings.
When installation has finished, make sure you leave both of these checked:
Update Malwarebytes' Anti-Malware
Launch Malwarebytes' Anti-Malware
Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
If you encounter any problems while downloading the definition updates, manually download them from HERE and just double-click on mbam-rules.exe to install.
On the Scanner tab:
Make sure the "Perform Quick Scan" option is selected.
Then click on the Scan button.
If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
Click on the Show Results button to see a list of any malware that was found.
Make sure that everything is checked, and click Remove Selected.
When removal is completed, a log report will open in Notepad.
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
Step 3
Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete. 1. At the main page. Press on " Accept". After reading the contents. 2. At the next window Select Update. Allow the Database to update. Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run. 3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete. 4. Select Scan Report. 5. If any threats were found they will appear in the report 6. Select "Save error report as" Then in the file name just type in kaspersky Under "save as type" select text .txt Save it to your Desktop. Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
1) CFScript references Spybot Search and Destroy. I had uninstalled Spybot. Is this what you wanted?
2) CFScript also references Lavasoft (Adaware). I had also uninstalled that. Is this what you wanted?
3) When I downloaded Malwarebytes, a "Task Manager program on steroids" called Anvir Task Manager asked me for permission to allow Malwarebytes to load onto my computer. I clicked "yes" and then I turned Anvir Task Manager off.
4) I saw the report from Malwarebytes after running it last night, but now (this morning) I can't find it. I thought it was in the Program Files/Malwarebytes folder. So I did a Search of All Files and Folders for "mbam" and only found an mbam log from December of 2009.
5) It took almost an hour to load the Kaspersky database, and the computer scan ran for so long, I left it running overnight. This morning I saw that it ran for 4:22:01, but there was NO report. Is this right?
If you can tell me what to redo, that would be great. I'm about to run Malwarebytes right now because I know I saw an mbam results file.
BTW, I don't know how to turn off the Windows Firewall. Should I? I guess it saved my butt last night because ZoneAlarm and Avira Antirus were off all night while the computer was on all night. Anything could have attacked my computer.
So all I have right now is the results of Combofix running CFSript. :-(
ComboFix 10-07-18.05 - Paul 07/19/2010 21:25:37.3.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1367 [GMT -4:00] Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Paul\Desktop\CFScript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
- - End Of File - - 6C6B1FCCBF70D334E61C931BA41B1649 -----------------------------------------------------------------------------------------------------------------------------
I`d like to see the other Malwarebytes log if possible please. Open Malwarebytes > Select the "Logs Tab" > from the list of logs look for the one we want by date/time. Select it and then open, that log will open in Notepad.
I asked you to delete the folders from the programs you uninstalled just to tidy up. Also Ask.com, dont let anything to do with Ask anywhere near your computer.
Regarding the Firewall, I`m sure that when you turn Zonealarm on, it turns the Windows Firewall OFF. To check the status of Windows F/W :-
Select Start > Control Panel > Security Center > Under "Mange Security Settings For" select the Windows F/W > from there you can turn it on and off.
Regarding the Kaspersky log, you will not get one if it found nothing, we can double check with ESET just to be certain.
Step 1
Run ESET Online Scan
Hold down Control and click on the following link to open ESET OnlineScan in a new window.ESET OnlineScan
Click the button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on to download the ESET Smart Installer. Save it to your desktop.
Double click on the icon on your desktop.
Check
Click the button.
Accept any security warnings from your browser.
Check
Push the Start button.
ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
When the scan completes, push
Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Push the button.
Push
You can refer to
this animation by
neomage if needed.
Frequently asked questions available
Here
If your system is responding OK we can cleanup and set you free. Proceed as follows :-
Step 1
Remove Combofix now that we're done with it
Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
Please follow the prompts to uninstall Combofix.
You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
It will also reset your system restore cache and create a fresh clean restore point.
Step 2
Download OTC by OldTimer and save it to your Desktop.
Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
Then Click the big button.
You will get a prompt saying "Begining Cleanup Process". Please select Yes.
Restart your computer when prompted.It will also remove the OTC application.
Step 3
Your Java is out of date.Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Read the License Agreement, and then check the box that says: "Accept License Agreement".
Click Continue and the page will refresh.
Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator. -- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it. -- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.
Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it:
Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.
Post a final HJT log and let me know if you have any specific issues.
I reran the Kaspersky program. Again, there was no report because there were no "threats found", no "infected objects found", and no "suspicious objects found". It scanned 194,036 objects in 4:24:37.
I haven't done what you asked yet. I thought you'd want to see the report of an Avira Antivirus scan that I started around noon. I'll wait for your reply to this before I do the actions you recommended above. - Paul
Avira AntiVir Personal Report file date: Tuesday, July 20, 2010 12:39
Scanning for 2369320 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : PAUL-9C407A28F4
Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium
Start of the scan: Tuesday, July 20, 2010 12:39
Starting search for hidden objects. '46409' objects were checked, '0' hidden objects were found.
The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'ForceField.exe' - '0' Module(s) have been scanned Scan process 'vsmon.exe' - '0' Module(s) have been scanned Scan process 'zlclient.exe' - '0' Module(s) have been scanned Scan process 'taskmgr.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'iPodService.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'RichVideo.exe' - '1' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'ISWSVC.exe' - '0' Module(s) have been scanned Scan process 'BCMWLTRY.EXE' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 28 processes with 28 modules were scanned
Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found!
Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found!
Starting to scan executable files (registry). The registry was scanned ( '56' files ).
Starting the file scan:
Begin scan in 'C:\' C:\hiberfil.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. C:\pagefile.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\WINDOWS\ERDNT\cache\atapi.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis. C:\WINDOWS\system32\dllcache\atapi.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis. C:\WINDOWS\system32\drivers\atapi.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis. Begin scan in 'D:\'
Beginning disinfection: C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was moved to '4c75eba5.qua'! C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was moved to '48500d1e.qua'! C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was moved to '4db50496.qua'! C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was moved to '4db71566.qua'!
End of the scan: Tuesday, July 20, 2010 14:31 Used time: 1:36:17 Hour(s)
The scan has been done completely.
18697 Scanned directories 781502 Files were scanned 7 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 4 Files were moved to quarantine 0 Files were renamed 2 Files cannot be scanned 781493 Files not concerned 4816 Archives were scanned 5 Warnings 6 Notes 46409 Objects were scanned with rootkit scan 0 Hidden objects were found
Yep they were contained in old restore points (System restore cache) When we uninstall Combofix with the command I gave in previous reply; aswell as removing itself and all associate files and folders, it also flushes the sys restore cache and creates a new clean restore point for you.
I like to use Kaspersky as my preferred online scan because it only identifies infected files folders etc, it doesn`t remove/quarantine anything. Then I can apply my fix accordingly.
When you run Avira it will remove the infected file/folder etc, as will ESET and other online scans. A poisoned restore point is sometimes preferrable to no restore points at all. We can restore to an infected state if required incase the PC will not boot etc. With no restore points you dont have that option.
Run the cleanup procedure I gave you, post a fresh HJT log and let me know of any specific issues, or if all is ok.
kevinf80_1d0ac6
2 Intern
•
1131 Posts
2984
0
Posted July 18th, 2010 09:00
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
Please proceed as follows :-
Step 1
We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Combofix
Don`t forget Combofix must be saved to your desktop. <--Very important
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <--- Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
Examples of how to disable realtime protection available at the following link :-
Disable realtime protection
Step 2
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Let me see logs from Combofix and Security Checks in your reply please.
Kevin