Win64 Sirefef Windows 7 Pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by kelley, Jun 21, 2012.

  1. kelley

    kelley Private E-2

    Last night I was attempting to find a unicorn game for my daughter to play and I went to a site that told me I had to update or install a flash player I clicked thru to prompts to update or install and immediately got a pop up that Windows was shutting down in 60 seconds. I have managed to get around this error by hitting F2, F8, choosing Repair Windows and System Restore I restored it to the day before this happened. I have followed all of the instructions thus far. I got to the part where I download and launch and update malware antibytes and my problem returned advising me the system would shut down in 60 seconds and I was unable to launch any of the other downloaded tools. I had to do system restore to post this. The only one that I could run was the Rogue Killer. I am attaching that file. Thanks So Much for your time.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to Start Menu > Run > (Type in) shutdown -a Now are you able to continue on with the Read and Run Me?
     
  3. kelley

    kelley Private E-2

    Ok I did the command in run and it went well. I had to redownload Hitman Pro and MG since I had done a system restore after I downloaded those yesterday. Now, I am back to the part where I disable the user account controls and the instuctions say I am to reboot after this. If I reboot I will be back to the original problem of the pop up message saying the system will shut down in 60 seconds. I am "assuming" that I could type the shutdown -a in the run box to stop this but you know how assuming is, so I want to be sure what the next step is. Reboot after disabling user account controls and type the shutdown -a in the run box or not to reboot? Thank You SO much.:)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes go ahead and disable User Account Controls, reboot and then you can enter in the command to prevent shutdown again. :)
     
  5. kelley

    kelley Private E-2

    Ok attaching the Malwarebytes log file and the Hitman Pro as well as the one I attached earlier for the Rogue Killer. Running into problems with the MG TOOLS, I disabled MSE, When I run MG TOOLS at the end it says - zip error could not create output file (C:/MGlogs.zip) Finished zipping filelog.txt ***Scanning complete your log file is C:\MGlogs.zip*** Hitting any key will close this command prompt window. - I have searched EVERYWHERE on this computer and cannot find this zipped MG log file. I do notice how there is a forward slash in the first one and a backward slash in the second one. Does this mean something? Also to locate the mblog file I had to go to C:\Users\Acer User\AppData\Roaming. I did disable users as we talked about in the previous message and did do a restart. Thank You:)
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)



    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. kelley

    kelley Private E-2

    Attached. Thank you MUCH.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    Now Run FRST again like you did in post # 6 and attach the log.

    How are things running now?
     

    Attached Files:

  9. kelley

    kelley Private E-2

    Sorry it took me so long to reply, got caught up in some other stuff. I could only find one log file to attach....it sounded like in your last message that there should be "2" logs that I am attaching?? Everything seems fine now, but I want to be sure before I start putting personal info out there again. I am getting one error message when I boot up but I don't think it is related to the virus but, rather, in my attempt to clean the virus before I contacted you guys I think I deleted something I wasn't suppose to. The error message after starting up is that a little box pops up and says: "Failed to find CONCENTR. CHM with error 2: The system cannot find the file specified." and then it gives the option to click "ok" . After I click ok nothing happens.
    Thanks again MUCH!
    Kelley
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem.

    Yep, because I had typed:
    ;)
    Relates to Citrix.

    You are very welcome. :) Just attach that log and we'll see what gives.
     
  11. kelley

    kelley Private E-2

    I "think" this is it....thanks again :)
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I deleted my last post because I thought there was one bad line left in your log but there is not. Everything certainly looks good now, is it running well? :)
     
  13. kelley

    kelley Private E-2

    Yes, running well. :) I appreciate you SO much!!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds