We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Trojan/Virus! Help!

I was looking at an obscure, American cookery website yesterday when I had a beep from my PC and a note from Avira saying that TR/Crypt.XPACK.Gen had been detected. I pressed the 'deny access' button and thought that was that.

Looking at the 'events' log on Avira today, it claims that TWO detections of this were made yesterday and that I 'allowed access' for one of them, which is complete nonsense.

I'm really shocked and worried because, googling this thing, it seems it can keylog banking passwords, hijack the browser and all sorts of other nasties.

Apparently I have this thing on my PC, even though it seems to be running normally in all regards today.

Can anyone tell me what to do, bearing in mind that I'm a technical illiterate and think that a hard drive is getting from Bristol to Bath?
«1

Comments

  • GunJack
    GunJack Posts: 11,863 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    first off, do a full scan with avira - it should pick it up, as it did so when you are on the site.

    next, download, update and quick scan with mbam
    http://www.filehippo.com/download_malwarebytes_anti_malware/

    delete all it finds and post the log back here...

    easy starter for 10 :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • LizEstelle
    LizEstelle Posts: 1,559 Forumite
    edited 20 March 2011 at 12:50PM
    GunJack wrote: »
    first off, do a full scan with avira - it should pick it up, as it did so when you are on the site.

    next, download, update and quick scan with mbam
    http://www.filehippo.com/download_malwarebytes_anti_malware/

    delete all it finds and post the log back here...

    easy starter for 10 :)

    Not such an easy starter, Jack.

    Already scanned with Avira. It picked up zilch. Ditto with Malwarebytes although this was only a 'quick scan'. I shall try a full one.
  • LizEstelle
    LizEstelle Posts: 1,559 Forumite
    Ok, I really would appreciate some help with this now. A full Malwarebytes scan reveals nothing, as does an Avira scan itself despite the fact that it was the Avira Guard which gave the warning.

    Can anyone help, please?
  • debitcardmayhem
    debitcardmayhem Posts: 12,960 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    LizEstelle wrote: »
    Ok, I really would appreciate some help with this now. A full Malwarebytes scan reveals nothing, as does an Avira scan itself despite the fact that it was the Avira Guard which gave the warning.

    Can anyone help, please?

    Is your Malwarebytes up to date? Post the log here and then see if someone can help
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • LizEstelle
    LizEstelle Posts: 1,559 Forumite
    Fully up to date. I always check for updates before I run a scan.

    The log is hardly worth looking at:

    Malwarebytes' Anti-Malware 1.50.1.1100
    https://www.malwarebytes.org

    Database version: 6092

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 7.0.6002.18005

    20/03/2011 17:23:42
    mbam-log-2011-03-20 (17-23-42).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 282633
    Time elapsed: 1 hour(s), 3 minute(s), 17 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • GunJack
    GunJack Posts: 11,863 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I've seen that with avira before, not normally something to worry about. However, you could run combofix as a last check

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    and post the log back here :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • LizEstelle
    LizEstelle Posts: 1,559 Forumite
    Thanks.

    What exactly is this and would downloading it cause any incompatibilities? I use Vista Basic, Chrome and, as mentioned, have Avira installed already.
  • GunJack
    GunJack Posts: 11,863 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Combofix is a powerful malware remover. all you need to do is turn off avira before you run combofix. Download and save it to desktop before running CF. It will prompt you to turn avira off before it starts scanning
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Using IE7 doesn't help your security much. Suggest you update to IE8, which you should have got automatically via Windows Updates.
    No free lunch, and no free laptop ;)
  • GunJack
    GunJack Posts: 11,863 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    macman wrote: »
    Using IE7 doesn't help your security much. Suggest you update to IE8, which you should have got automatically via Windows Updates.

    gotta be honest, I still use IE7 on this pc with XP...don't like 8 much compared to 7. Mind you, use Opera more than IE these days...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.