Avast WEBforum

Other => Viruses and worms => Topic started by: anusmyn on December 16, 2011, 03:11:41 AM

Title: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 16, 2011, 03:11:41 AM
I ran avast and this came up as a threat:
C:\Windows\assembly\GAC_32\Desktop.ini      Threat: Win32:Sirefef-FQ [Drp]
I can't get rid of it!!! What do I do?!
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: DavidR on December 16, 2011, 03:16:10 AM
- This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 (http://forum.avast.com/index.php?topic=53253.0) for information on Logs to assist in cleaning malware. Use the information about getting and using the logs and attach the logs here, not in the LOGS topic.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 16, 2011, 05:03:57 AM
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8377

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

15/12/2011 7:13:29 PM
mbam-log-2011-12-15 (19-13-29).txt

Scan type: Quick scan
Objects scanned: 179319
Time elapsed: 6 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files (x86)\common files\akkg.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files (x86)\common files\akkg1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files (x86)\common files\insta.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files (x86)\common files\insta1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 16, 2011, 05:10:17 AM
Here is the OTL log. I can't print screen for some reason.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 16, 2011, 05:36:39 AM
aswMBR has made my computer crash and blue screen twice...  ???
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: DavidR on December 16, 2011, 12:49:07 PM
At what point, during the AV scan element ?

If so try running it again and from the AV scan: drop down list, select None as the scanning option.

The first time that you run OTL it should also produce an Extras file, if you can attach that.

Unfortunately you may be playing time zone ping pong as essexboy who normally analyses these is at work and is usually on the forums around 7pm (now almost 11:50am in the UK).
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 17, 2011, 12:13:23 AM
Here is the OTL extra file.
aswMBR crashes at 1%...
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 17, 2011, 12:18:09 AM
When set to none answMBR works fine. Here is the log.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 17, 2011, 12:33:56 AM
Ok, so I tried to run a quick scan and aswMBR errors at 1% on agrdel64.exe then blue screens.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on December 17, 2011, 01:07:39 PM
I see you have run combofix - could you attach that log please
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 17, 2011, 04:01:47 PM
Sorry... I'm not sure where it is...
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on December 17, 2011, 04:41:20 PM
It should be at C:\combofix txt

If it is not there then we will re-run it as I need to see if there is a driver remaining

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 18, 2011, 12:40:13 AM
Here it is. Thanks for the help.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on December 18, 2011, 12:02:26 PM
What are your current problems ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 19, 2011, 01:27:50 AM
Here is ODT log. Running scan now.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 19, 2011, 02:35:43 AM
According to avast! I am still infected with this:
C:\Windows\assembly\GAC_32\Desktop.ini      Threat: Win32:Sirefef-FQ [Drp]
 :-[
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 22, 2011, 12:34:08 AM
...?
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: DavidR on December 22, 2011, 02:05:07 AM
It may still be a remnant, but are you getting any of the other symptoms ?

Unfortunately it is 1:05am in the UK so essexboy will be in bed and normally back on the forums after work about 7pm UK time.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on December 22, 2011, 09:01:40 PM
Could you re-run an OTL please with the following script

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
C:\Windows\assembly\GAC_32\*.ini
/md5stop
C:\Windows\assembly\tmp\U\*.* /s
CREATERESTOREPOINT

Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 24, 2011, 08:32:05 AM
Here is the OTL log.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on December 24, 2011, 08:32:52 AM
Here is the extras log.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on December 24, 2011, 11:35:10 AM
Hmm that showed one file that should not be there

color=green]Download and Install Combofix[/color]
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on January 09, 2012, 12:50:48 AM
Sorry, I was away on holidays and had no access to a computer.
Here is the log from Combofix.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on January 18, 2012, 08:51:51 AM
Help! ???
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: DavidR on January 18, 2012, 02:42:12 PM
Because of the delay essexboy may not be subscribed to this topic, I will PM him to notify.

I'm afraid that you may be in for a little time zone ping pong as it 1:42pm in the UK and essexboy may not be back in the forums until later in the day around 7pm.
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on January 18, 2012, 02:45:25 PM
Hi there are the alerts still occuring ?
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: DavidR on January 18, 2012, 02:50:49 PM
Thought you would be at work essexboy ;D
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on January 18, 2012, 03:16:41 PM
Nope taking a few days off  ;D
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on January 20, 2012, 01:59:02 AM
Scan finds this:
C:\_OTL\MovedFiles\12182011_132538\C_Windows\...Destop.ini Threat Win32:Sirefef-FQ [Drp]
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on January 20, 2012, 01:50:43 PM
That is the OTL quarantined file

Any other problems ?
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: anusmyn on January 22, 2012, 04:08:01 AM
Nope!
Title: Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
Post by: essexboy on January 22, 2012, 01:31:01 PM
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Remove ComboFix

.
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
(http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif)
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
SPRING CLEAN

To manually create a new Restore Point
 Now we can purge the infected ones
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif)
Malwarebytes (http://www.malwarebytes.org/mbam-download.php).  Update and run weekly to keep your system clean

Download and install FileHippo update checker (http://www.filehippo.com/updatechecker/) and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ? (http://www.geekstogo.com/forum/topic/225044-preventing-malware-and-safe-computing/)

Keep safe  :wave: