![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi,
I'm stuck with Microsoft Security Essentials detecting two trojans upon startup: Trojan:Win32/Sirefef.AB Trojan:Win64/Sirefef.P Located in: C:\Windows\assembly\GAC_32\Desktop.ini C:\Windows\assembly\GAC_64\Desktop.ini I ran everything on the READ & RUN ME (except RootRepeal as I got Windows 7 Professional x64). I hope I have attached all needed logs. P.S. I'm pretty sure that the KMService.exe in the MBAM log is a false positive (It's MSOffice activator). |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Also this:
|
|
#3
|
|||
|
|||
|
By the way I also tried to run "aswMBR.exe" but after a while it crashes on me.
|
|
#4
|
||||
|
||||
|
It looks like Combo cleared the infection. What issues are remaining, if any?
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#5
|
|||
|
|||
|
Quote:
Should I retry Combo? |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Yes, re-run Combo and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach both logs.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#7
|
|||
|
|||
|
Here's the logs after Combo and MGtools re-run.
|
|
#8
|
||||
|
||||
|
Uninstall the below old versions of software:
Java(TM) 6 Update 30 Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#9
|
|||
|
|||
|
I followed all the instructions but the two Desktop.ini are still there and still infected (after rebooting and scanning with MSSE).
Don't tell me I shouldn't have re-enabled MSSE after the ComboFix. Also during the MGtools scan I'm getting this message: "Ordinal 1108 could not be located in dynamic link library WSOCK32.dll" Here are the logs: |
|
#10
|
||||
|
||||
|
Please do the below so that we can boot to System Recovery Options to run a scan.
For 32-bit (x86) systems downloadFarbar Recovery Scan Tool and save it to a flash drive. For 64-bit (x64) systems downloadFarbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options: Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Here's the log.
(Issue is still there after the reboot.) |
|
#12
|
||||
|
||||
|
Download this >> fixlist.txt
Save fixlist.txt to your flash drive.
Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#13
|
|||
|
|||
|
LOGS→HERE
From the prompt windows it seemed that MGtools couldn't scan c:\Windows\assembly\GAC_32\Desktop.ini *ACCESS DENIED* |
|
#14
|
||||
|
||||
|
You have the most recent form of Zero Access infection. We have some mode hidden stuff to find to get this fully fixed. Let's try another fix followed by a using a new version of MGtools.
Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Download this >> fixlist.txt Save fixlist.txt to your flash drive.
Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
Thanks chaslang for helping me with this infection. It seems like a bad one.
I did everything you said but it didn't help much, apparently. Here are the logs you asked for. |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Okay, now run the C:\MGtools\ZAchk.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
Then attach the below log which should have been updated after running the above:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#17
|
|||
|
|||
|
Done.
|
|
#18
|
||||
|
||||
|
Delete your current copy of ComboFix.exe and then download and save the current version to your Desktop. Get it here >> combofix.exe
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#19
|
|||
|
|||
|
OK, now it seems that the files have been deleted (I rebooted twice).
Now I'm going to reboot re-activating MSSE at startup. Let's see... Meanwhile, LOGS: |
|
#20
|
|||
|
|||
|
Yes! Everything seems good now!
Thanks for your precious help. I can't thank you enough. Is there anything else I should do now to be sure the malware has gone forever? |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trojans: Win32/Sirefef.AB and Win64/Sirefef.P | gravanov | Malware Removal | 4 | 06-03-12 20:25 |
| Trojan:Win32/Sirefef.AB & Win64/Sirefef.P | Smokejumper | Malware Removal | 2 | 05-30-12 16:50 |
| Win32/Sirefef.DA trojan | CRD72 | Malware Removal | 6 | 11-18-11 07:32 |