![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi,
My ESET antivirus has notified me that I am infected with the win32/Sirefef.DA trojan. It says that it is in the operating memory and that it could not remove it. If someone would be able to help me remove it I would greatly appreciate. Thank you for your time. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to the Malware Removal Forum.
Please read ALL of this message including the notes before doing anything. Pleases follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs when you finish these instructions.
Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
I was also having redirecting problems with FireFox, so I followed the steps and here is my GooredFix logfile:
GooredFix by jpshortstuff (03.07.10.1) Log created at 23:20 on 13/11/2011 (Mushi) Firefox version 7.0.1 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [07:45 21/05/2011] {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [16:59 05/05/2010] {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [04:59 07/07/2011] C:\Documents and Settings\Mushi\Application Data\Mozilla\Firefox\Profiles\egjb1qv8.default\extensions\ {20a82645-c095-46ed-80e3-08825760534b} [17:48 03/03/2011] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [00:06 09/04/2010] "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [16:59 05/05/2010] -=E.O.F=- |
|
#4
|
||||
|
||||
|
Quote:
I would also like to see logs from running the other procedures I linked you to:
Then you will have finished running the procedures and I can properly analyse all the logs.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
I've run all of the scans that were asked and here are the logs.
|
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
And here is the MGTools logs.
|
|
#7
|
||||
|
||||
|
Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Win32.Sirefef Trojan disabling my anti-rootkit | execute | Malware Removal | 3 | 11-22-09 10:38 |
| Trojan-Downloader.Win32.Small.ivp and Trojan-PWS.tanspy | jaimej78 | Malware Removal | 16 | 08-16-08 15:32 |
| Trojan.Klone.H, Win32:Dialer-gen13 or Trojan.Downloader.Small.CML | lanche | Malware Removal | 11 | 11-07-06 22:21 |
| New Trojan Trojan-Downloader.Win32.Agent.cf | alonge | Malware Removal | 3 | 05-03-05 00:16 |
| win32/trojan downloader.ISTbar.EN trojan; win32/trojan dropper.bridge.A trojan | vlatko27 | Software | 1 | 05-27-04 08:40 |