Zeroaccess Variant 'Sirefef' Discussion

Discussion in 'Malware Help (A Specialist Will Reply)' started by vahnx, Jul 31, 2012.

  1. vahnx

    vahnx Private E-2

    I've been successfully keeping the place I've been working at since I started a year and a half ago virus free, that is until yesterday. I came into work only to hear the guy in the office next to me screaming at his machine. He had 'Live Security Platinum' installed. First thing I did was unplug the network cable, and after running MBAM and several other tools I was able to get rid of it. Then at the end of the day someone brought in their personal laptop and they wanted me to install a program for them, but then when I booted I noticed this Live Security Platinum installed on it. This personal laptop wasn't even connected to the network; so my question was "How did he get it too?". He claims his PC was fine before he brought it in.

    I'm thinking there is some outbreak going on. Does anyone know any further insight to this virus? Googling it comes up with many discussions and it seems to have "hit hardest" within the past day, yet I see no news articles or nothing covering it, other than forums with people posting Hijack this logs and whatnot getting it fixed. I want to know what's causing it. The guy I fixed yesterday claimed he was just surfing Google looking for Ontario maps.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Don't know for sure, but did you use any USB flashdrives on the first PC and then did you plug it into the second PC?

    Also had both PCs been connected to the network?

    HijackThis logs are a thing of the past. They are of very little use these days.

    And by the way, the first PC you believe you cleaned may not really be clean. I suspect you have a ZeroAccess infection ( aka Sirefef ).
     
    Last edited: Aug 1, 2012
  3. vahnx

    vahnx Private E-2

    The initial guy was on the network but the second guy brought his personal laptop which wasn't even connected (and no USBs were passed around). And yes, the first desktop is clean and did have the ZeroAccess variant 'Sirefef', as the title suggests. I'm not wondering how to clean it, I just want to know information about it. How does it get on ones system? Is it coming from a common Google search string that leads to a malicious site or what? Just seems strange two completely different people get hit by the same virus within 2 days and I haven't dealt with user viruses in a long time.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many different ways are possible. One of the most recent common ways is via a fake Adobe Flash Player update.

    If you check the threads here you will see greater than 90% of requests for help are due to ZeroAccess infections. This is a common trend all over the world.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds