MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 06-06-12, 18:29
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Sirefef-A attack!

Hi,

A few days ago, Avast started giving warnings of the following Trojan's:
- Sirefef-A
- DNS Changer VJ
It started whilst my wife was browsing the net on various Russian websites - but not using sites that should be considered overly dangerous.

I have run two Avast full scans and two boot scans and Avast is detecting and quarantining the viruses but they still seem to be activated each time the computer was started, with further Avast warnings. Also, my internet connection was being 'altered' so that I had to run network diagnostics and then restart the computer to get online. Internet Explorer also seemed to be running very slowly, to the point of the whole system freezing regularly.

So, I have tried to follow the steps in the Read and Run-Me First guide and the Windows XP Malware removal procedure (logs attached).

Super Anti-spyware ran and did not detect anything.

Malwarebytes picked up and deleted a few trojans.

The problems started with Combofix and then repeated with RootRepeal because each time the computer froze not long after beginning the scanning process. I have tried a number of times with each of them and I have attempted to run them in Safe Mode - but with no success.

MGTools also ran successfully.

After running Malwarebytes, Avast has stopped issuing warnings and I have had no problems getting online. However, I am deeply suspicious that I still have some Malware that is interrupting Combofix and RootRepeal and my browser (Internet Explorer) still seems to be running very slowly and intermittanly freezing.

My thanks in advance for your assistance. This has been driving me crazy for a few days now!!

Cheers,
Al.
Attached Files
File Type: txt mbam-log-2012-06-06 (13-19-47).txt (3.3 KB, 9 views)
File Type: zip MGlogs1.zip (142.0 KB, 9 views)
File Type: log SUPERAntiSpyware Scan Log - 06-06-2012 - 13-13-08.log (574 Bytes, 2 views)
Reply With Quote
Sponsored links
  #2  
Old 06-07-12, 03:03
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Welcome to MajorGeeks, Al

From Add/Remove Programs (via Control Panel), please uninstall the below:
  • Java(TM) 6 Update 22
  • J2SE Runtime Environment 5.0 Update 7

Please download Disable/Remove Windows Messenger to your desktop.
  • Double-click MessengerDisable.exe to run it.
  • Place checkmarks in "Uninstall Windows Messenger" and "Hide Messenger from Outlook Express"
  • Click Apply
  • Click Exit

Please download BlitzBlank to your desktop.
  • Double-click BlitzBlank.exe to open (Vista/7 right-click and select Run as Administrator)
  • Press OK at the warning prompt.
  • Click the Script tab
  • Copy the text inside the code box below and paste it into the text-field.
Code:
DeleteFolder:
C:\WINDOWS\Installer\{f7ce0457-08e3-b544-c563-b4c545a5c8e0}
"C:\Documents and Settings\Admin_2\Local Settings\Application Data\{f7ce0457-08e3-b544-c563-b4c545a5c8e0}"
  • Now click the Execute Now button.
  • The fix will require a reboot in order to complete successfully.
  • Upon reboot, locate C:\blitzblank.log and attach this log to your next message. (How to attach)

__

Attempt to run ComboFix using these directions:
  • Press and hold the Windows key and then press the letter R on your keyboard.
  • This opens the Run dialog box.
  • Copy and paste the below text inside the text-field:
    • "%userprofile%\desktop\ComboFix" /killall
  • Now press ENTER
  • ComboFix should launch and try to scan. Let me know exactly what happens if it does not run successfully this time around.
  • Attach C:\ComboFix.txt if it was successful. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-08-12)
  #3  
Old 06-08-12, 06:16
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Hello,

I'm very grateful for your help so far - thanks very much!

I managed to follow your instructions as far as running Combofix and the BlitxBlank log is attached.

When I came to run Combofix. I disabled my antivirus and firewall and then ran the program from the run dialog box as per your instructions. Combofix loaded - with the dialog box with the green bar - it created a system restore point and then came up with the window which says "scanning for infected files....... This typically doesn't take more than 10 minutes" etc.

Soon after, the computer froze. I rebooted and attempted to run Combofix again from the run dialog box and it reached the same point. This time the computer didn't freeze straight away, although it didn't appear to be doing anything either. I left it running overnight and by morning, it had frozen at the same stage. There didn't appear to be any sign of Combofix having worked at all - the clock format hadn't changed and the internet connection was still active.

Is there anything else to try? Thanks again for your help.
Attached Files
File Type: log blitzblank.log (4.5 KB, 9 views)
Reply With Quote
  #4  
Old 06-08-12, 12:16
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Hello.

Follow these instructions and remember to attach the log once the scan is finished: ESET Online Scanner
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-09-12)
  #5  
Old 06-09-12, 18:47
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Hi,

The ESET scan ran successfully - log attached.

Thanks again!
Attached Files
File Type: txt ESETScan.txt (391 Bytes, 7 views)
Reply With Quote
Sponsored links
  #6  
Old 06-09-12, 18:49
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

How is the system running at this point?
__________________
Facebook . Twitter . Blog . VirusTotal

Last edited by thisisu; 06-10-12 at 11:12.. Reason: typo
Reply With Quote
  #7  
Old 06-10-12, 05:57
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Hi,

The system is running but it is still running more slowly than it was before. I also have a problem with loading webpage pictures - they appear as square icons with a red cross inside. This is happening across all webpages, compared with only rare occurences before

I also just attempted to run Combofix as per your previous instructions and the system is still hanging at the same point.

However, Avast is no longer giving any warnings at start up and I can at least browse the internet, which is a big improvement on how things were before!
Reply With Quote
  #8  
Old 06-10-12, 12:11
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

I do not think malware is the cause of ComboFix and RootRepeal not running. It's probably some other type of Windows issue or maybe your low capacity / legacy 20GB hdd is the problem. We'll run a couple more checks just to make sure.

The ESET scan looks very good.

__

As for your other problem with images not showing up. You may want to try this: Microsoft Fix it 50195

__

I want you to read and follow these instructions: TDSSKiller - How to run

__

Please download OTL by OldTimer.
  • Save it to your desktop.
  • Double click on the OTL icon on your desktop.
  • Check the "Scan All Users" checkbox.
  • Check the "Standard Output".
  • Change the setting of "Drivers" and "Services" to "All"
  • Copy the text in the code box below and paste it into the text-field.
    Code:
    activex
    netsvcs
    /md5start
    afd.sys
    i8042prt.sys
    ipsec.sys
    netbt.sys
    services.exe
    svchost.exe
    /md5stop
    %windir%\$ntuninstallkb*. /30
    %windir%\system32\drivers\*.sys /lockedfiles
  • Now click the button.
  • One report will be created:
    • OTL.txt <-- Will be opened
  • Attach OTL.txt to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-10-12)
  #9  
Old 06-10-12, 17:17
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Many thanks once again for your help and advice!

My computer is quite a few years old, so maybe I do need to think about an upgrade! On the other hand, it did seem to be running fine before these problems started last week.

Unfortunately, the Microsoft Fix didn't completely cure the pictures issue. I'll try a few more things once the system is completely clean to try to resolve that.

In the meantime, I did manage to run TDSKiller and OTL. TDS Killer found one unsigned file. OTL crashed the first time with a BSOD but ran fine the second time round. It produced two logs, I guess you only want the first one OTL.txt, but I've attached them both just in case.

There doesn't seem to be any change in the operation of the system post-scan and pre-scan.
Attached Files
File Type: txt OTL.Txt (158.4 KB, 6 views)
File Type: txt Extras.Txt (24.9 KB, 1 views)
File Type: txt TDSSKiller.2.7.36.0_10.06.2012_22.50.10_log.txt (77.3 KB, 3 views)
Reply With Quote
  #10  
Old 06-10-12, 17:50
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Fix items using OTL by OldTimer

Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Copy the text in the code box below and paste it into the text-field.
Code:
:otl
SRV - [2011/06/26 07:45:56 | 000,256,000 | R--- | M] () [Auto | Stopped] -- C:\ComboFix\pev.3XE -- (PEVSystemStart)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rootrepeal.sys -- (rootrepeal)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O33 - MountPoints2\{8ae19a44-aebb-11df-a634-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{8ae19a44-aebb-11df-a634-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8ae19a44-aebb-11df-a634-806d6172696f}\Shell\AutoRun\command - "" = E:\SmartAccess\ConnectGo.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2012/06/09 23:40:22 | 000,047,807 | ---- | M] () -- C:\WINDOWS\WPCSET.BIF
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:C31F31E6
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
:files
C:\WINDOWS\Installer\{f7ce0457-08e3-b544-c563-b4c545a5c8e0} /d
C:\Documents and Settings\Admin_2\Local Settings\Application Data\{f7ce0457-08e3-b544-c563-b4c545a5c8e0} /d
dir /s C:\WINDOWS\$NtUninstallKB2718704$ /c
c:\windows\system32\wevtutil.exe cl Application /c
c:\windows\system32\wevtutil.exe cl Security /c
c:\windows\system32\wevtutil.exe cl Setup /c
c:\windows\system32\wevtutil.exe cl System /c
:reg
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"00PCTFW"=-
"Adobe ARM"=-
:commands
[clearallrestorepoints]
[emptytemp]
[resethosts]
Now click the button.
If the fix needed a reboot please do it.
Click the OK button (upon reboot).
When OTL is finished, Notepad will open. Close Notepad.
A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Attach this log to your next message. (How to attach)

Now run C:\MGtools\GetLogs.bat by double-clicking it.
This updates all of the logs inside MGlogs.zip.
When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-10-12)
Sponsored links
  #11  
Old 06-10-12, 18:37
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

I ran OTL and it required a reboot. In the process of shutting down for the reboot, the system crashed on a BSOD re "Driver Corrupted MMPool". Upon the restart, OTL finished running and produced a log (attached). Immediately, I then received 2 window's messages saying that the "system has recovered from a serious error". I have attached the details in a file called serious error.txt.

GetLogs.bat ran successfully - log attached.

Many thanks once again for your help!
Attached Files
File Type: log 06112012_002111.log (15.3 KB, 7 views)
File Type: zip MGlogs.zip (139.7 KB, 4 views)
File Type: txt serious error.txt (856 Bytes, 4 views)
Reply With Quote
  #12  
Old 06-10-12, 19:12
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Can you attach this file? C:\Documents and settings\Admin_2\LOCALS settings\Temp\WER7d28.dir00\Mini060612-01.dmp

It may also be in here: C:\Windows\Minidump
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #13  
Old 06-10-12, 20:06
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Unfortunately I can't attach the file directly. The uploader won't allow *.dmp extensions.

I've attempted to load the file into WinDbg and the copy and paste the results into the attached .txt file. I fear, however, the results may not be very useful
Attached Files
File Type: txt debug.txt (13.0 KB, 2 views)
Reply With Quote
  #14  
Old 06-10-12, 20:12
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

I just had an idea and added a .txt extension to the end of the .dmp file to try and trick the uploader into allowing me to attach the file and it's worked! Hopefully, you can open it more successfully than me
Attached Files
File Type: txt Mini060612-01.dmp.txt (88.0 KB, 1 views)
Reply With Quote
  #15  
Old 06-10-12, 20:43
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Did these bluescreens just start or has this been going on for a while?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #16  
Old 06-11-12, 07:29
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

We did have a problem with bluescreens a few years ago but I cleared that by re-installing windows from the original CD.

Since then, we have had blue screens very rarely. There have been quite a few over the last week, mainly whilst running cleaning programs / fixes.

Thanks, Al.
Reply With Quote
  #17  
Old 06-11-12, 13:28
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

To me it sounds like there may be a problem with the computer's memory/RAM.

This typically isn't the scope of this forum and you may need to pursue any remaining issues in a different subforum but this is a quick way to test memory:

http://www.memtest.org/
http://www.memtest.org/download/4.20...+-4.20.iso.zip <-- burn the .ISO as an image to a blank CD.
Boot from the CD.
Let me know if you start seeing red lines fill up the screen, like this:

The red means failed memory (at least one stick).
If there's no red after a couple of passes, then we can rule out memory.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-15-12)
  #18  
Old 06-11-12, 15:26
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

Also, please run C:\MGtools\FixNet.bat
It will run a few commands and then reboot your computer.

Once your computer has been rebooted:

Now download the latest MGtools.exe to the root of your c: drive.
  • Replace your existing MGtools.exe with this one.
  • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
  • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal

Last edited by thisisu; 06-11-12 at 15:36..
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (06-15-12)
  #19  
Old 06-15-12, 18:27
AlDibb AlDibb is offline
Private E-2
 
Join Date: Feb 2009
Posts: 17
Thanks: 10
Thanked 0 Times in 0 Posts
Default Re: Sirefef-A attack!

Hi,

Sorry not have posted sooner - I've been away from home for a few days.

OK, I ran the memory test and it did two passes - both successful - with no errors found.

I followed your instructions with MGTools and the log is attached.

Thanks again for your advice - I will be away again for a while but I will really appreciate any further help on my return.

Al.
Attached Files
File Type: zip MGlogs.zip (152.1 KB, 2 views)
Reply With Quote
  #20  
Old 06-15-12, 23:06
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Sirefef-A attack!

I'm glad to hear memtest passed

Your latest logs are clean.
What malware related problems are you still having, if any?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
AlDibb (07-05-12)
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojans: Win32/Sirefef.AB and Win64/Sirefef.P gravanov Malware Removal 4 06-03-12 20:25
Trojan:Win32/Sirefef.AB & Win64/Sirefef.P Smokejumper Malware Removal 2 05-30-12 16:50
Sirefef Fun Time Troubles mikeymasonic Malware Removal 10 05-27-12 02:07
Sirefef Trojan pike8 Malware Removal 21 01-29-12 20:29
Win32/Sirefef.DA trojan CRD72 Malware Removal 6 11-18-11 07:32


All times are GMT -5. The time now is 10:00.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger