Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Crypt Xpack Trojan OH NO!  (Read 5287 times)

0 Members and 1 Guest are viewing this topic.

esistkai

    Topic Starter


    Starter

    Crypt Xpack Trojan OH NO!
    « on: January 02, 2009, 04:53:06 PM »
    I've been so frustrated by this stupid virus for the last few days, and I have forms to fill out for school that I'm not comfortable doing with a potential keystroke tracker or anything else nasty. I appreciate the steps proposed in the forum to fix my machine, and on the surface, it looks to be removed. I'd just be thrilled to have one of you help me check the logs.

    Thanks in advance!

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 01/02/2009 at 06:37 PM

    Application Version : 4.24.1004

    Core Rules Database Version : 3688
    Trace Rules Database Version: 1664

    Scan type       : Complete Scan
    Total Scan Time : 00:26:56

    Memory items scanned      : 317
    Memory threats detected   : 0
    Registry items scanned    : 4371
    Registry threats detected : 0
    File items scanned        : 31078
    File threats detected     : 0


    Malwarebytes' Anti-Malware 1.31
    Database version: 1456
    Windows 5.1.2600 Service Pack 2

    1/2/2009 6:48:45 PM
    mbam-log-2009-01-02 (18-48-45).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 73644
    Time elapsed: 9 minute(s), 1 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:49:27 PM, on 1/2/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Acer\eRecovery\Monitor.exe
    C:\Acer\eManager\anbmServ.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\WISPTIS.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows NT\Accessories\wordpad.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
    F2 - REG:system.ini: Shell=explorer.exe
    O2 - BHO: (no name) - {0117E4BC-8A6F-4845-AFE3-CA4D23143F58} - C:\WINDOWS\system32\fccbAQhE.dll (file missing)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
    O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [msiexec.exe] msiconf.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [msiexec.exe] msiconf.exe (User 'Default user')
    O4 - Startup: Nikon Monitor.lnk = ?
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O20 - AppInit_DLLs: dhzpav.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: opnoPFuT - opnoPFuT.dll (file missing)
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    --
    End of file - 5831 bytes

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: Crypt Xpack Trojan OH NO!
    « Reply #1 on: January 04, 2009, 05:13:29 PM »
    Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://subs.geekstogo.com/ComboFix.exe

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double-click combofix.exe and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey

    esistkai

      Topic Starter


      Starter

      Re: Crypt Xpack Trojan OH NO!
      « Reply #2 on: January 04, 2009, 09:57:37 PM »
      My browser apparently has been hijacked; I can't go to any legitimate site to download combofix. I looked through a bunch of sketchy links, but don't really want to introduce any new trojans. Where is the best place to find the program, other than bleeping computer and such?

      You're so patient and helpful! Thanks!

      CBMatt

      • Mod & Malware Specialist


      • Prodigy

      • Sad and lonely...and loving every minute of it.
      • Thanked: 167
        • Yes
      • Experience: Experienced
      • OS: Windows 7
      Re: Crypt Xpack Trojan OH NO!
      « Reply #3 on: January 05, 2009, 04:34:27 PM »
      Try this...

      Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
      • Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
      • Then search for TDSSserv.sys
      • Let me know if you find this or not.
      • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
      • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.
      .

      And then...

      Please print these instructions as they will be needed later when Internet access is not available.
       
      Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/179891642/SDFix.exe.html

      When using this tool, you must use the Administrator's account or an account with Administrative rights
      • Double click SDFix.exe and it will extract the files to %systemdrive%
      • (this is the drive that contains the Windows Directory, typically C:\SDFix).
      • DO NOT use it just yet.
      .Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
       
      Open the SDFix folder and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
      • Copy and paste the contents of the results file Report.txt in your next reply.
      Don't try ComboFix again until you've gotten back to me about these new instructions first.
      Quote
      An undefined problem has an infinite number of solutions.
      —Robert A. Humphrey

      esistkai

        Topic Starter


        Starter

        Re: Crypt Xpack Trojan OH NO!
        « Reply #4 on: January 09, 2009, 03:02:24 PM »

        SDFix: Version 1.240
        Run by Chris on Fri 01/09/2009 at 04:53 PM

        Microsoft Windows XP [Version 5.1.2600]
        Running From: C:\SDFix

        Checking Services :


        Restoring Default Security Values
        Restoring Default Hosts File

        Rebooting


        Checking Files :

        Trojan Files Found:

        C:\WINDOWS\antiv.exe - Deleted





        Removing Temp Files

        ADS Check :
         


                                         Final Check :

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-01-09 16:57:10
        Windows 5.1.2600 Service Pack 2 FAT NTAPI

        detected NTDLL code modification:
        ZwClose

        scanning hidden processes ...

        scanning hidden services ...

        HKLM\SYSTEM\CurrentControlSet\Services\SENSka

        scanning hidden autostart entries ...

        scanning hidden files ...

        C:\WINDOWS\system32\drivers\senekampyblhhb.sys 49152 bytes
        C:\WINDOWS\system32\drivers\seneka.sys 49152 bytes
        C:\WINDOWS\system32\senekadf.dat 16384 bytes
        C:\WINDOWS\system32\seneka.dat 16384 bytes
        C:\WINDOWS\system32\senekaevdyirtq.dll 16384 bytes
        C:\WINDOWS\system32\senekalrotpkds.dll 32768 bytes
        C:\WINDOWS\system32\senekalog.dat 49152 bytes
        C:\WINDOWS\system32\senekamloaqgom.dll 16384 bytes

        scan completed successfully
        hidden processes: 0
        hidden services: 1
        hidden files: 8


        Remaining Services :




        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
        "C:\\Program Files\\Microsoft Office\\Office12\\groove.exe"="C:\\Program Files\\Microsoft Office\\Office12\\groove.exe:*:Enabled:Microsoft Office Groove"
        "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

        Remaining Files :


        File Backups: - C:\SDFix\backups\backups.zip

        Files with Hidden Attributes :

        Sun  9 Nov 2008         1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK7.dll"
        Sun  9 Nov 2008         1,024 ...HR --- "C:\WINDOWS\system32\NTIMPEG2.dll"
        Sun  9 Nov 2008         1,024 ...HR --- "C:\WINDOWS\system32\NTIFCD3.dll"
        Sun  9 Nov 2008         1,024 ...HR --- "C:\WINDOWS\system32\NTIBUN4.dll"
        Sun  9 Nov 2008         1,024 ...HR --- "C:\WINDOWS\system32\NTIMP3.dll"
        Mon 14 Mar 2005       299,008 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\Maint.exe"
        Mon 28 Feb 2005        61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\uinstrsc.dll"

        Finished!


        CBMatt

        • Mod & Malware Specialist


        • Prodigy

        • Sad and lonely...and loving every minute of it.
        • Thanked: 167
          • Yes
        • Experience: Experienced
        • OS: Windows 7
        Re: Crypt Xpack Trojan OH NO!
        « Reply #5 on: January 10, 2009, 07:56:45 PM »
        Try this...

        Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
        • Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
        • Then search for TDSSserv.sys
        • Let me know if you find this or not.
        • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
        • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

        Are you able to download and run ComboFix now after doing this?
        Quote
        An undefined problem has an infinite number of solutions.
        —Robert A. Humphrey