Avast WEBforum

Other => Viruses and worms => Topic started by: RK90217 on July 25, 2012, 09:11:42 PM

Title: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 25, 2012, 09:11:42 PM
Topic infections, not even sure what else. Not very tech savvy, so I apologize in advance if i'm a bit slow to figure things out. Will post FSS log in next post.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 25, 2012, 09:13:01 PM
FSS logs attached. Let me know if I need anything else, help is much appreciated.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 25, 2012, 09:17:50 PM
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.  :)
----------

Download Combofix from either of the links below, and save it to your desktop. 
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

**Note:  It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 25, 2012, 09:35:31 PM
Thank you for the quick reply. I would prefer to not have to reformat my computer because I have over 900GB of programs on it, but if that is the best solution then I will do what needs done, just let me know. For now, I hope we can just clean it without a reformart. Combofix log attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 25, 2012, 10:58:15 PM
Also, if it comes to me having to reformat, how would I go about reinstalling windows without a cd? I just looked for my windows cds and i'm not able to find them, is there a way to create one or would I need to purchase a new windows 7 disc?
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 26, 2012, 03:08:51 AM
Hi,

I think we are looking pretty good so far.  :)
-------
Code: [Select]
ClearJavaCache::

DDS::
uStart Page = hxxp://www.gamefaqs.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>

Firefox::
FF - ProfilePath - c:\users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\9q7r6kjw.default\
FF - prefs.js: keyword.URL - hxxp://lf.startnow.com/s/?src=addrbar&provider=bing&provider_name=bing&provider_code=Z051&partner_id=276&product_id=709&affiliate_id=&channel=4000&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110727&user_guid=F0203CEFC2E04D67947DF704045137A8&machine_id=e52e6371d6f187a616c5360c832d60ee&browser=FF&os=win&os_version=6.1-x64-SP1&q=

RegNull::
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\KISS\«0¹0¿0à0á0¤0É03*D*]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{030C80EA-F8BC-29D4-E59D-AA88D3ABEF35}*]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \Installation]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \rUGPBasic]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \rvmmBoxSettings]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \rvmmInstallation]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \rvmmPeculiarToTheApp]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\’}*’u*’0 ’ ’I*’9 ’^*’l*’C*’e*’B*’ \rvmmUISettings]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\Installation]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\InstallFont]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\PeculiarToTheApp]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\rUGPBasic]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\rvmmBoxSettings]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\rvmmInstallation]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\rvmmPeculiarToTheApp]
[HKEY_USERS\S-1-5-21-2358422974-4226417570-1287725948-1000\Software\relic UGP Applications\age\Þ0Ö0é0ô01*1*\rvmmUISettings]
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 03:34:02 AM
Thank you again for the help, attached the combofix log.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 26, 2012, 02:00:00 PM
Hi,

Malwarebytes

I see that you have Malwarebytes already on your computer.  Please open Malwarebytes, update it and then run a Quick Scan.  Save the log that is created for your next reply.
----------

Please run a free online scan with the ESET Online Scanner (http://www.eset.com/onlinescan/)
Note: You will need to use Internet Explorer for this scan[/i]**Note** If not threats are found there will not be a log created.
----------
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 08:45:34 PM
Malware bytes did not find any infections, but at first it would see the 0000008.@ if I did quick scan, and I did a restart after the "removal" when I first noticed the infection and the next time it would not find it during a quick scan. I did a full scan just to be sure, and it found the same 0000008.@ in the same spot, only it no longer finds it during quick scans. Once I realized it couldn't remove it, that's when I decided to come here because I wasn't sure what to do. Not sure if that information helps, but I figured I would post it just in case.

Both logs attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 26, 2012, 09:50:00 PM
Please delete the current version of Combofix.exe from your desktop and download a new version from here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your desktop.

Disable your AntiVirus and AntiSpyware applications.

Right-click and Run as Administrator on the Combofix.exe and follow the prombts on your display. When finish, it will create a C:\Combofix.txt. Please post this log for further review.
---------
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 10:08:01 PM
Combofix log attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 26, 2012, 10:56:55 PM

For x64 bit systems download Farbar Recovery Scan Tool x64 (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[/list]
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 11:27:16 PM
I tried booting it up and pressing F8 and it doesn't seem to bring anything up. I also do not have my windows installation disc, in an earlier post I asked if I could create one or if I needed to purchase a new one. I don't have the money currently to buy a new disc(I believe they are $100-200?), so i'm out of luck on that unfortunately.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 11:33:19 PM
Apologies, I wasn't pressing it at the right time apparently. Running the tool now.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 26, 2012, 11:38:16 PM
FRST Log attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 27, 2012, 03:48:32 AM
Hi,

Good job getting that ran.  :)

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

Code: [Select]
C:\Users\Ray\AppData\Local\{11c0699d-a9a9-0e7d-359f-ce1f5d08d031}

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 27, 2012, 03:59:26 AM
Log attached.  :)
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 27, 2012, 01:48:35 PM
Hi,

Good job.  Please run a new scan with ESET and attach the new log.
----------

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or here (http://screen317.changelog.fr/SecurityCheck.exe).----------
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 27, 2012, 08:43:43 PM
Both logs attached.

I'm guessing security check was to see if I had an antivirus or something? This computer was given to me not long ago, and I had not installed an antivirus yet. For future reference, what is the best antivirus to use? (I won't install anything unless told to of course)
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 28, 2012, 04:22:06 AM
Well in my opinion I would recommend above all others Avast.  It is just really good.  :)  You can download it here >> Avast (http://www.avast.com/en-au/free-antivirus-download)

Adobe Reader

You have an older version of Adobe Reader.  You can download the current version HERE (http://www.adobe.com/products/acrobat/readstep2.html)

You may want to consider   Foxit Reader (http://www.foxitsoftware.com/downloads/index.php) instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum (http://www.foxitsoftware.com/bbs/forumdisplay.php?f=3)

In either case you should uninstall Adobe Reader 9 first. Be sure to move any PDF documents to another folder first though.
----------

How is your system running?
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 28, 2012, 04:35:49 AM
Ok, thanks much for the information, updating right away.

The system seems to be running perfectly fine now, no browser site re-routes and what not. That's how I originally came to the conclusion I had an infection. By what the logs said, it seems the problems are quarantined I guess?
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 29, 2012, 06:42:40 PM
Providing there are no other malware related problems...

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D  SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees.  As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
----------

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run  and copy/paste the following text into the Run box as shown and click OK.
  Combofix /Uninstall
  (Note: There is a space between the ..X and the /U that needs to be there.)

(http://i1224.photobucket.com/albums/ee380/jeffce74/CF.jpg)
----------

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
If you didn't already have it I would keep Malwarebytes AntiMalware though.


Here are some tips to reduce the potential for spyware infection in the future:

1. Internet Explorer.  Even if you don't use it as your main browser it should be kept up-to-date because that is the browser Windows uses for updates.
Make your Internet Explorer more secure
- This can be done by following these simple instructions:
2. Enable Protected Mode in Internet Explorer.  This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code.  To make sure this is running follow these steps:3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly.  I would personally only recommend using one of the following two below:
Online Armor Free (http://download.cnet.com/Online-Armor-Free/3000-10435_4-10426782.html)
Agnitum Outpost Firewall Free (http://download.cnet.com/Agnitum-Outpost-Firewall-Free/3000-10435_4-10913746.html)

5. Make sure you keep your Windows OS currentWindows XP users can visit Windows update  (http://v4.windowsupdate.microsoft.com/en/default.asp)  regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.  Without these you are leaving the back door open.

6.   WOT   (http://www.mywot.com/) (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites.  WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?  (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
 
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 29, 2012, 08:03:03 PM
Downloaded Online Armor and installed WOT Addon to all browsers. Now another problem arises, whenever I try to update windows I get an error, It's error 80246008. It won't let me download any updates at all due to the error.

Edit: I was looking it up, and someone said it's due to BITS Service. I looked in the services from admin tools and it's not listed there. I'm guessing the infection deleted it?

Edit 2: I just scanned registry for issues with CCleaner, and a few things caught my eye.
Activex/com issue - whitesmoke_bar/prxtbWhit.dll
and
Missing TypeLib reference - ISearch

I looked those two up and apparently they are both spyware or something? I don't want to click "Fix Selected Issues" because I don't know what it will do with those two.

Also another thing was obsolete software key - swearware, but I think that is from uninstalling ComboFix.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 29, 2012, 11:32:05 PM
Yeah that was from ComboFix.

Let's see what your BITS service looks like.

Please download Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and run it on the computer with the issue.----------
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 30, 2012, 12:02:55 AM
Log Attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 30, 2012, 02:43:43 AM
Hi,

Code: [Select]
@echo off
regedit.exe /e "%userprofile%\Desktop\look.txt" "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS"
Notepad.exe %userprofile%\Desktop\look.txt
Del look.txt
Del %0
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 30, 2012, 02:59:27 AM
Here we are.

---------

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS]
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
  00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 30, 2012, 03:10:09 AM
Hi,

Is that all there was? 
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 30, 2012, 03:16:20 AM
Yes, I did select all when I copied, so I shouldn't have missed anything.


Edit: Also, what should I do with the CCleaner registry tool about Activex/com issue - whitesmoke_bar/prxtbWhit.dll and Missing TypeLib reference - ISearch?
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 30, 2012, 03:42:22 PM
Hi,

Just in case you removed it do the following...

Please download and run ERUNT (http://www.snapfiles.com/get/erunt.html) (Emergency Recovery Utility NT).  This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.  **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
----------

Next I would like you to take the following steps:
Code: [Select]
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS]
"DisplayName"="@%SystemRoot%\\system32\\qmgr.dll,-1000"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001"
"ObjectName"="LocalSystem"
"ErrorControl"=dword:00000001
"Start"=dword:00000002
"DelayedAutoStart"=dword:00000001
"Type"=dword:00000020
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,45,00,76,00,65,00,\
  6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,00,00
"ServiceSidType"=dword:00000001
"RequiredPrivileges"=hex(7):53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,\
  00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
  67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
  00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
  00,00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,\
  00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,00,\
  72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,\
  63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
  00,01,00,00,00,60,ea,00,00,01,00,00,00,c0,d4,01,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Performance]
"Library"="bitsperf.dll"
"Open"="PerfMon_Open"
"Collect"="PerfMon_Collect"
"Close"="PerfMon_Close"
"InstallType"=dword:00000001
"PerfIniFile"="bitsctrs.ini"
"First Counter"=dword:000007d2
"Last Counter"=dword:000007e2
"First Help"=dword:000007d3
"Last Help"=dword:000007e3
"Object List"="2002"
"PerfMMFileName"="Global\\MMF_BITS_s"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,a0,00,00,00,14,00,00,00,34,00,00,00,02,\
  00,20,00,01,00,00,00,02,c0,18,00,00,00,0c,00,01,02,00,00,00,00,00,05,20,00,\
  00,00,20,02,00,00,02,00,5c,00,04,00,00,00,00,02,14,00,ff,01,0f,00,01,01,00,\
  00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\
  20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,\
  00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,02,\
  00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,05,20,00,00,\
  00,20,02,00,00
----------

Once complete run a new scan with FSS and attach the new log. 
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 30, 2012, 06:15:34 PM
Log Attached.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 30, 2012, 10:11:36 PM
Hi,

Please go to Start >> type Run in the Start Search bar >> in Run type Services.msc >> Next to Background Intelligent Transfer Service you will see columns.  Find the column labeled Startup Type across from BITS.  Double click on the startup type (Manual, Automatic, Disabled...) and then in the General tab under Startup type make sure it is set to Manual.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 30, 2012, 10:17:47 PM
There isn't a Background Intelligent Transfer Service in my services at all. Whenever I mentioned the BITS service earlier, I had looked in my services and it wasn't there then either. So from then till now, nothing has changed, so i'm not sure what's up with it.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: RK90217 on July 31, 2012, 07:16:08 AM
After a restart, the BITS service has shown back up and is working. I left the computer on while trying to deal with the infection, so it seems all it needed was a simple restart. Apologies for the "wild goose chase", I didn't know that would fix it, but should have done so anyways.

Everything seems fine now, i'm able to update my windows and no problems seem to have come up now. Thank you very much for the help. If there is anything else that needs done, let me know in case i'm missing something. I'll check back until you give me the OK.
Title: Re: 0000008.@ Infection and Sirfef infection help
Post by: jeffce on July 31, 2012, 01:27:42 PM
Great!  I should have thought of that too!  LOL!!  Anyway...I think we are done here.  It was nice working with you.  :)