Need help removing Win32 trojans in Vista: Fereit.gen!C & Sirefef.A

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mal0613, Jun 13, 2013.

  1. Mal0613

    Mal0613 Private E-2

    Greetings and salutations!

    I am writing to request help removing some trojans from my Windows Vista system.

    I foolishly tried to watch a TV show online yesterday, June 12, 2013) around 4am. It was a sketchy site I'd never been to before, accessed using FireFox, and I was hit w/ some trojans. Windows immediately told me it had updated, and wanted to restart. That was suspicious, so I ran a full system scan w/ Microsoft Security Essentials, and then Spybot Search & Destroy.

    MS Security Essentials identified these two files, and cleaned them:
    Win32/Fereit.gen!C
    Win32/Sirefef.A

    Spybot Search & Destroy found some additional stuff, which I also deleted/fixed, but don't recall what.

    I downloaded, installed, and ran Malwarebytes. It found some stuff, and cleaned it. Unfortunately, I didn't immediately enable the realtime protection trial, as I thought it wanted money. That is up and running now, and nothing was found on subsequent scans.

    As part of my attempts at cleanup/protection, I installed something called SpywareBlaster, which appears to be similar to SpyBot in locking down host files. However, a bunch of stuff that Spybot used to kill at Startup is running again. That's a separate issue, but I wanted to mention it in case the SypwareBlaster software was relevant.

    I deleted Adobe Flash, and Reader, to keep them from compromising me until I'm clean.

    I deleted Java, to keep it from potentially addind something.

    I reset NoScript's white list in Firefox, so that I don't accidentally let something in through a previously trusted site.

    I wasn't confident these measures were sufficient to root out all the trojans, and didn't want my passwords compromised, especially banking; so I did some searching and found the MajorGeeks page.

    I've now followed your Vista & Windows 7 Malware Removal instructions.

    RougeKiller found some hidden stuff labelled: HJ and HJ DESK. I ignored it, and have attached the log.

    Malwarebytes, as stated before, found something prior to using your instructions, but nothing since. I have attached the original log & the most recent.

    TDSSKiller didn't find anything, so there is no log.

    HitmanPro found something, and I attached the log: "HKLM\SOFTWARE\Classes\s\ (Softonic)"

    MGTools zip is attached as well.


    I am not sure how to tell if I am still having problems, since I am mostly concerned about removing the trojans and associated programs.

    Thanks, in advance, for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  3. Mal0613

    Mal0613 Private E-2

    Great! Thanks for your help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds