Win32:Sirefef, Win32:ZAccess, Win32Trojan, Win32:Malware-gen

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jshinabe, Jul 21, 2013.

  1. jshinabe

    jshinabe Private E-2

    Hi,

    I have read and followed all of the READ ME First instructions and uploaded all of the logs.

    I have Avast and saw such viruses as:

    Win32:Malaware-gen
    Win32:Trojan-gen
    Win32:Sirefef-PL [Rootkit]
    HTML:RedirME-inf [Trj]

    Thank you for any help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 7 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\Run : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\RunOnce : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\RunOnce : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : bdaefbdaedfdfad (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\Run : bdaefbdaedfdfad (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Jenn\AppData\Local\{40021656-4d6d-26e9-ca6e-3085e6c4f832}\n. [x]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for items on the file/folder tab, please...

    • [ZeroAccess][Folder] U : C:\Windows\Installer\{40021656-4d6d-26e9-ca6e-3085e6c4f832}\U [-] --> FOUND
    • [ZeroAccess][Folder] L : C:\Windows\Installer\{40021656-4d6d-26e9-ca6e-3085e6c4f832}\L [-] --> FOUND
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Rerun Hitman and have it delete Malware remnants if any show.

    Delete these if you see them:

    C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad
    C:\Windows\tasks\{A9923236-EC59-4483-A8AE-194C87B575A9}.job

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. jshinabe

    jshinabe Private E-2

    Ran RogueKiller and put checks next to the seven files below and deleted them.

    • [RUN][SUSP PATH] HKCU\[...]\Run : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\Run : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\RunOnce : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\RunOnce : Adobe CSS5.1 Manager (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : bdaefbdaedfdfad (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3525285151-1972300058-3382392559-1001\[...]\Run : bdaefbdaedfdfad (C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad\bdaefbdaedfdfad.exe [-]) -> FOUND
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Jenn\AppData\Local\{40021656-4d6d-26e9-ca6e-3085e6c4f832}\n. [x]) -> FOUND

    I moved to quickly to the next stop and did not check the File/Folder tab. I ran RogueKiller again and they files didn't show up under the File/Folder tab. I attached both logs.

    I rebooted the machine and ran Hitman, no Malware remnants showed. Log is attached.

    I deleted the two files listed below.

    C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad
    C:\Windows\tasks\{A9923236-EC59-4483-A8AE-194C87B575A9}.job

    I ran MGTools by mistake instead of MGTools\GetLogs.bat. I ran MGTools\Getlogs.bat. Both times I received a message that Steelwerx stopped working.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    I received an Error Report an the end of the process that the C:\MGLogs.zip failed to be created along with File Not Found.

    Thank you for your time.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the C:\MGtools\ReZip.batfile by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator), then look in the C:\MGtools folder for a slightly different zip file named MGlogsR.zip Attach it to your next message.
     
  5. jshinabe

    jshinabe Private E-2

    The MGlogsR.zip file is attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 3 you never attached the new requested logs from Hitman Pro and RogueKiller.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Also, how are things working?

     
  7. jshinabe

    jshinabe Private E-2

    The Hitman Pro and Roguekill logs are attached.

    Copied text below and received no success message.


    Things are working much better! There have been no redirects in browsers, system is not bogged down and I don't see any issues that I was having before. Many thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you run another scan with RogueKiller, does the below still appear?

    If so, see if RogueKiller can delete it.

    Check to see if the below folder exists and delete it if it does:
    C:\Users\Jenn\AppData\Local\217b5d83-aef6-4b4d-a997-e0d286f0df22ad
     
  9. jshinabe

    jshinabe Private E-2

    I ran RogueKiller again, log attached.

    I think that the I deleted the file based on message 2 and 3. I looked for the file again but did not see it there.

    Machine still running great and no pops and redirects anymore.

     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is good now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds