TR/Crypt.EPack with assorted issues

Posted 29 June 2011 - 05:33 PM


Since last night I have been having some difficulty with my computer. As I haven't seen issues identical or close to mine on the forums I thought it best to begin my own thread.

My computer runs Windows 7.

The first problem I noticed was the presence of an adware program, with a fake scan, trying to sell something like "Windows 7 Pro 2012". In order to stop this from running, I went into Task Manager and killed a program yil.exe (I think yil means nothing, and it was just three random letters). At this point I disconnected from the internet and tried to run MalwareBytes, but this started yil.exe again, so I killed yil a second time.

Next, I searched for "yil.exe" in my file system and found it in c:/users/<My user name>/AppData/Local/Temp. I deleted it along with several other files in this directory created during the same minute as "yil.exe". The adware no longer comes up, however, I still have the following problems:

- Google redirects to non-malicious but nonsensical sites when clicking through a search
- Most significantly, the computer will no longer run .exe files. I have been able to get firefox and one other application to run by going into the "C:\Program Files" folder and clicking directly on the program file when prompted (for example, when clicking on the Firefox shortcut, if windows asks what to use to open firefox.exe, I can go into C:\Program Files\Mozilla and click on firefox.exe, which will open firefox.)

At the outset, I also ran Avira, which found and quarantined TR/Crypt.EPACK.Gen2.

In order to resolve the .exe issue (in order to be able to do System Restore, etc.) I've tried USB-ing two exe fix files from this website (one was a .reg), but neither were able to complete running.

Finally, just an hour ago I was able to run MalwareBytes by renaming it as a .bat, and it found no malicious files (this is version

Therefore, I think it's time to stop trying to use your efforts from afar, and to ask for your help directly. Can you help? If so, what logs can I provide?

Thank you,

Edited by hamluis, 29 June 2011 - 05:38 PM.
Moved from win 7 to Am I Infected.

Posted 29 June 2011 - 08:12 PM

Welcome aboard Posted Image

To help with your .exe files...
Download and run exeHelper.

  • Please download exeHelper from Raktor to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • A log file named log.txt will be created in the directory where you ran exeHelper.com
  • Attach the log.txt file to your next message.

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Download Security Check from HERE, and save it to your Desktop.

* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

Posted 29 June 2011 - 09:12 PM

Hi Broni! Thanks for the very quick reply.

OK, here is my information. FYI, in case it matters, I am downloading all of these files on a second computer, to avoid connecting the infected machine to the Internet.

1) Exehelper.com - this program was unable to complete. The error message I got was simply "exehelper.com has stopped working". However, upon reboot (at the end of all 3 steps) I tried to open a few programs and they were able to open, as opposed to before.

exeHelper by Raktor
Build 20100414
Run at 21:22:58 on 06/29/11
Now searching...
Checking for numerical processes...

2) Security check - Here is my log:

Results of screen317's Security Check version 0.99.7
Windows 7 (UAC is enabled)
Internet Explorer 8
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
Norton Internet Security
McAfee Security Scan Plus
WMI entry may not exist for antivirus; attempting automatic update.
Avira successfully updated!
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 22
Adobe Flash Player
Adobe Reader 9.4.0
Out of date Adobe Reader installed!
Process Check:
objlist.exe by Laurent

Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````End of Log````````````

3. MalwareBytes - Found and fixed four problems in the registry. Here is the log.

Malwarebytes' Anti-Malware

Database version: 6705

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/29/2011 9:38:00 PM
mbam-log-2011-06-29 (21-38-00).txt

Scan type: Quick scan
Objects scanned: 156634
Time elapsed: 4 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\SB1979\AppData\Local\yil.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\SB1979\AppData\Local\yil.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\SB1979\AppData\Local\yil.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Posted 29 June 2011 - 09:19 PM

Very well....
You're running two AV programs, Norton and Avira.
One of them has to go.
If Norton, make sure to use this tool to uninstall it: http://us.norton.com/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN


You can safely uninstall McAfee Security Scan Plus, typical foistware.


1. Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.


Update Adobe Reader

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.


Is the redirection still present?
If so, which browser is affected?

Please download Rootkit Unhooker from one of the following links and save it to your desktop.
Link 1 (.exe file)
Link 2 (zipped file)
Link 3 (.rar file)In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can download, install and use the free 7-zip utility.

  • Double-click on RKUnhookerLE.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
-- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".

Posted 30 June 2011 - 06:37 PM


Some updates:

I was able to uninstall Norton and McAfee Security Scan Plus, and to install Adobe Reader X.
When installing the latest Java (6.26), I got a message "wrapper.createfile access is denied." However, the version appears to have installed.
The Javara and Unhooker logs are here. I apologize for the length, I'm not sure how to attach a file here on this forum.
This may or may not be significant, but when I tried to save the Unhooker report through the File menu, the program closed and automatically put a three line report on my desktop. I've posted that below, too.
Firefox, which is the only browser I use, still redirects occasionally.

JavaRa 1.16 Removal Log.

Report follows after line.


The JavaRa removal process was started on Thu Jun 30 19:25:16 2011

Finished reporting.

Nothing detected :(

Posted 30 June 2011 - 10:01 PM

Firefox, which is the only browser I use, still redirects occasionally.

Can you check, if same issue happens in IE?

Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode).
If you're using Firefox 4, go Help>Restart Firefox with Add-ons Disabled.
Same issue?

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click [b]Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Posted 01 July 2011 - 05:15 AM

The same redirections occur, on roughly every fifth google search, in both Firefox and Firefox Safe Mode. I tried about twelve searches in IE and no redirections happened.

Here is the Gooredfix log.

GooredFix by jpshortstuff (
Log created at 06:05 on 01/07/2011 (SB1979)
Firefox version 5.0 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [23:13 30/06/2011]
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [00:48 22/03/2011]
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [22:37 30/06/2011]

C:\Users\SB1979\Application Data\Mozilla\Firefox\Profiles\mtqtb9m9.default\extensions\

(Key not found)


Posted 01 July 2011 - 07:50 PM

Can you check, if same issue happens in IE?

Posted 01 July 2011 - 08:09 PM

Based on my experiments so far, no redirections have happened with IE.

Posted 01 July 2011 - 08:59 PM

Create FF new profile and see if same issue happens.

Posted 02 July 2011 - 05:35 AM

I've tried between ten and twenty searches and there have been no redirections. The connection to get to legitimate sites was slow and that has become faster, too. Will creating this new profile require me to do anything different on start-up?

Even if we aren't finished yet, thanks again for your help. I never would have come anywhere close to figuring out what to do on my own.

Posted 02 July 2011 - 11:11 AM

Very well :)
It looks like there was something in your old FF profile, which was causing redirection.
If you have some important bookmarks in your old profile, log in to it, export bookmarks, log out, log in to your new profile and import old bookmarks.
Then delete your old profile (instructions in the very same link above).

Now, couple more things I want you to do to make sure your computer is clean....

Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.


Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

Posted 04 July 2011 - 09:18 PM

Sorry for the delay the last few days, I was out of town and it was hard to find time to monitor the full ESET scan.

The ESET scan completed with no threat files found. I couldn't find a way to get a log, I am figuring that because the scan didn't find anything, a log wasn't created. Regardless, that is good news!

Posted 04 July 2011 - 09:58 PM

Good news :)

Your computer is clean Posted Image

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll remove all old restore points and create fresh, clean restore point.

Turn system restore off.
Restart computer.
Turn system restore back on.

If you don't know how to do it...
Windows XP: http://support.microsoft.com/kb/310405
Vista and Windows 7: http://www.howtogeek.com/howto/windows-vista/disable-system-restore-in-windows-vista/

2. Make sure, Windows Updates are current.

3. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

4. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

5. Run Temporary File Cleaner (TFC) weekly.

6. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

7. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

Posted 11 July 2011 - 01:04 PM

Thank you for the tips. Everything has been running very well, thanks to your help, but (my apologies) I have one more question on this. I am getting a warning that the Windows Security Center service can't be started. I checked and that's because it doesn't exist anymore in the list of services. I imagine the malware that you helped me clean out destroyed it originally.

In the Microsoft forums I saw that you can download and import a replacement: (http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/084209d7-81c7-47f5-85e4-1eb532bac8ba, look for "Niki Han" entry)

In your opinion, is this safe to do?

