Avast WEBforum

Other => Viruses and worms => Topic started by: darkmata on March 12, 2012, 01:59:50 PM

Title: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 01:59:50 PM
Hi, my PC is infected with sirefef and/or ZEROACCESS and i think i've followed your instructions on this post(if not please tell me..):http://forum.avast.com/index.php?topic=53253.0

i'm attaching the results on the tests and the logs. I'll be so thankful for your help!

thanks in advance.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 02:04:57 PM
Also i have to say, that i have purchased the Avast!internet security for 2 years, and everytime i'm installing it, on the next reboot pc doesn't load windows, then it automatically goes to windows will try to scan for errors and try to fix them, well Windows is not able to repair, so all i can do is turn off PC or go to restore windows to previous date, well i restore and then i go when the Antivirus is not installed...and this forever an ever in a loop...

thanks again.
P.D:i'm attaching the last file i have...
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 02:10:00 PM
Hi,

Download Combofix from either of the links below, and save it to your desktop. 
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

**Note:  It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://"http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216")

--------------------------------------------------------------------
Code: [Select]
ClearJavaCache::

File::
C:\Windows\SysNative\bb-run.dll
C:\Windows\SysNative\dds_log_ad13.cmd
C:\Windows\SysNative\dds_log_trash.cmd

Registry::
Netsvc::
snoopfreesvc

Driver::
snoopfreesvc
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 02:23:27 PM
Hi Jeffce,
thanks for your help, ok now i run combofix but i cannot see the report, also it never restarts the pc, seems like it has finished scanning, window disappear and that's it...i'm not even touching the mouse or anything.

Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 02:30:03 PM
Hi,

Go to your C:\ folder and look for a file named Combofix.txt   If you see that please post that into your next reply.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 02:56:18 PM
sorry but there is no combofix.txt file... :-\
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 03:04:11 PM
would you like a tdsskiller report?
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 03:19:44 PM
i was reading on the essexboy post, and when i have to run OTL he says select ALL USERS..what does it mean, i'm never asked for that or cannot even see that to check it.
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 03:28:48 PM
Hi darkmata,

Seems like the ZeroAccess infection is preventing some of our tools that we need. 

Go ahead and run TDSSKiller but use these instructions and not those posted previously and then post the log created.

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)
----------
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 03:35:23 PM
Done.
No malicious found just one threat.i skiped.

thanks.
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 03:42:26 PM
Hi darkmata,

We need to make all files and folders VISIBLE:

Please delete your copy of ComboFix from your Desktop using right-click >> delete. 

Now visit the link here >> http://www.mediafire.com/?3wuubumznr3cs8h and download the file to your Desktop.  Once downloaded to your Desktop, run the program.  There will be a log produced I will need in your next reply.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 03:57:21 PM
Hi jeffce,

the same issue as before, it scans, looks like it has finished, but i'm not even able to close the window, it disappears and that's all, also on C: there is no report at all...

this is a hard stuff!!
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 04:07:55 PM
Hi jeffce

i have folder on C: named 32788R22FWJFW it's  like 12mb and it says that it shows all the harddrives and hardware connected to this pc.... ???

is that normal?
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 04:11:38 PM
Hi darkmata,

Don't worry about the folder.  I believe it is fine. 

I am going to work up a fix using OTL and will return as quick as I can.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 04:15:08 PM
 hi jeffce

ok , here are some roguekiller reports, maybe this could help!

thanks a lot!

P.D.: if you fix it...i'll send you good bottle of catalan wine! ::)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 04:59:48 PM
oh! :( i'm terribly sorry, i've noticed that those reports are on UTF-8, do you want them on ANSI?
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 12, 2012, 08:08:51 PM
Hi,

Please download ERUNT (http://www.snapfiles.com/get/erunt.html) (Emergency Recovery Utility NT).  This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.  **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
----------

Run OTL.exe
Code: [Select]
:Services

:OTL
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\bb-run.dll -- (snoopfreesvc)
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - SOFTWARE\Classes\CLSID\{db131c55-60c8-4adc-84dc-9e76ab06e2dc}\InprocServer32 File not found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851619
IE - HKCU\..\URLSearchHook: {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - SOFTWARE\Classes\CLSID\{db131c55-60c8-4adc-84dc-9e76ab06e2dc}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {FD63BF63-BFFF-4B8F-9D26-4267DF7F17DD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851619
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (uTorrentBar_ES Toolbar) - {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - C:\Program Files (x86)\uTorrentBar_ES\prxtbuTor.dll File not found
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar_ES Toolbar) - {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - C:\Program Files (x86)\uTorrentBar_ES\prxtbuTor.dll File not found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O33 - MountPoints2\{16478422-317d-11e1-9f37-00241d15fa81}\Shell - "" = AutoRun
O33 - MountPoints2\{16478422-317d-11e1-9f37-00241d15fa81}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
NetSvcs:[b]64bit:[/b] snoopfreesvc - C:\Windows\SysNative\bb-run.dll (Iomega)
[2012/03/12 13:33:01 | 000,000,000 | -HS- | M] () -- C:\Windows\SysNative\dds_log_ad13.cmd
[2012/03/02 12:54:55 | 000,000,000 | -HS- | C] () -- C:\Windows\SysNative\dds_log_trash.cmd
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

:Files
ipconfig /flushdns /c
dir C:\Users\Cure\AppData\Local\cf5171c8 /s /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 08:27:09 PM
Hi jeffce

i've done it all and post the log...
I don't know if you need anything else.
thanks a lot for your hard work!
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 08:54:54 PM
Hi jeffce

do i have to scan again with MBAM or any other prog.?

or maybe my pc is ok and i can do a party? :P
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 09:24:49 PM
Hi jeffce , sorry my fault didn't do the otl scan... :-X

here is the file...

thnx!
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 12, 2012, 09:33:07 PM
here is the OTL.txt file done just after rebooting fromthe fix on OTL...
i attached it because maybe it's different than if i have been using the pc for a while like before...
sry
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 01:16:07 AM
Hi there darkmata,

I see that you are running more than I ask you to do.  Please try to refrain from that as it may actually hinder our progress even though you have good intentions.  So please only run the tools I ask you to.  :)
--------

Seems like our fix hasn't taken yet.  Sometimes we need to hit this infection several times before it breaks.  I appreciate your patience.  :)
--------

Run ERUNT again to make a new backup of your registry.
--------

Run OTL.exe
Code: [Select]
:Services

:OTL
MOD - [2010/11/21 04:24:09 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\SiS300i.dll -- (co_mon)
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - SOFTWARE\Classes\CLSID\{db131c55-60c8-4adc-84dc-9e76ab06e2dc}\InprocServer32 File not found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851619
IE - HKCU\..\URLSearchHook: {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - SOFTWARE\Classes\CLSID\{db131c55-60c8-4adc-84dc-9e76ab06e2dc}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {FD63BF63-BFFF-4B8F-9D26-4267DF7F17DD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851619
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (uTorrentBar_ES Toolbar) - {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - C:\Program Files (x86)\uTorrentBar_ES\prxtbuTor.dll File not found
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar_ES Toolbar) - {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - C:\Program Files (x86)\uTorrentBar_ES\prxtbuTor.dll File not found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O33 - MountPoints2\{16478422-317d-11e1-9f37-00241d15fa81}\Shell - "" = AutoRun
O33 - MountPoints2\{16478422-317d-11e1-9f37-00241d15fa81}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
NetSvcs:[b]64bit:[/b] snoopfreesvc - C:\Windows\SysNative\bb-run.dll (Iomega)
[2012/03/12 13:33:01 | 000,000,000 | -HS- | M] () -- C:\Windows\SysNative\dds_log_ad13.cmd
[2012/03/02 12:54:55 | 000,000,000 | -HS- | C] () -- C:\Windows\SysNative\dds_log_trash.cmd
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

:Files
C:\Windows\SysNative\SiS300i.dll
ipconfig /flushdns /c
dir C:\Users\Cure\AppData\Local\cf5171c8 /s /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 08:28:03 AM
Hi jeffce,

sry for all the incovenience...and absolutely thanks for your support!when i try to do a new backup, an emerging message appears:
error saving file C:/windows/ERDNT/13-03-2012/BCD
continue with next file?
[ RegCreateKeyEX:5 - acces denied ]

I press yes, and same message but instead BCD, it changes it to system, software, default, security, sam, ntuser.dat and UsrClass.dat.

and then it appears "OK your backup is done"

now i'll try to run OTL, first fix , then scan.

thank you.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 08:38:01 AM
Hi Jeffce

this is the OTL report.

thanks agian.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 11:50:01 AM
Hi there darkmata,

I see that you are running more than I ask you to do.  Please try to refrain from that as it may actually hinder our progress even though you have good intentions.  So please only run the tools I ask you to.  :)
--------

[/list]

Hi jeffce, i've done that! ;)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 01:55:53 PM
Hi there jeffce,

just wanted to know if otl file is correct?or maybe i didi something wrong, but I don't know what. I just did what you tell me...and I runed the scan on the fresh reboot, nothing else.
well I'm sure you are still working on it, but maybe you need something else, if I can help you any other way just tell me.

thanks.
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 02:53:00 PM
Hi darkmata,

No everything is fine.  I am clarifying something with Essexboy before we continue.  Hang tight and I will return as quickly as I can.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 02:53:41 PM
ok thanks to both for your kindful help!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 08:55:54 PM
Hi darkmata,

Run OTL.exe
Code: [Select]
:Services

:OTL
MOD - [2010/11/21 04:24:09 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\SiS300i.dll -- (co_mon)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\ufdsvc.dll -- (swupdtmr)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\USBCamera.dll -- (SlNtHal)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\ati.dll -- (IFP700)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\networkx.dll -- (dmboot)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\U81xmdfl.dll -- (defragfs)

:Files
C:\Windows\SysNative\SiS300i.dll
C:\Windows\SysNative\ufdsvc.dll
C:\Windows\SysNative\USBCamera.dll
C:\Windows\SysNative\ati.dll
C:\Windows\SysNative\networkx.dll
C:\Windows\SysNative\U81xmdfl.dll
ipconfig /flushdns /c
dir C:\Users\Cure\AppData\Local\cf5171c8 /s /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 10:02:35 PM
Hi jeffce,

here is the report.

thanks a lot!

Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 10:24:50 PM
Hi,

Download Combofix from any of the links below but rename it to svchost.exe before saving it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.infospyware.net/antimalware/combofix)


==================================

Right-click and Run as Administrator on the renamed ComboFix.exe & follow the prompts.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 10:36:25 PM
Hi jeffce,

no combofix.txt created, so sorry...

I don't know what's wrong...

thanks again
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 10:41:56 PM
Hi jeffce

I supose mbam starts at windows start, the sometimes i get the prompt message of C:\windows\assembly\tmp\U\00000001.@

and sometimes two more with different numbers like 800000c0.@ and 800000cb.@

i don't know if it helps...
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 10:43:56 PM
Hi darkmata,

No need to say sorry.  :)

Run OTL.exe
Code: [Select]
:Services

:OTL
SRV:[b]64bit:[/b] - [2009/07/14 02:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\mcmscsvc.dll -- (mfesmfk)

:Files
C:\Windows\SysNative\mcmscsvc.dll

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 10:59:02 PM
Hi jeffce,

i asume that it has to be a hard work to code/decode all this stuff, and supose how frustrating sometimes this could be, that's wahy i say sorry... ;)

but i know you can! :P

better take this with humor isn't it?

ok here is the OTL file
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 13, 2012, 11:07:13 PM
LOL!!  I actually have a lot of fun doing this and helping people.  :)


Code: [Select]
@ECHO OFF
cd c:\
junction -s c:\>log.txt
start log.txt
del %0

Next,
Double click junc.bat to run it. (accept any alerts) A log will be presented. Copy and paste or attach the content of the log in your next reply.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 11:18:38 PM
lol! nice to hear that!

ok it gave me an error could not find log.txt file be sure that the file name is correct.
and behind that there is a window cmd.exe ,with "acces denied" written...

thanks.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 13, 2012, 11:32:21 PM
Also i have to say that if i try to extract the flie directly to c: it gives an error:

C:\Users\Cure\Desktop\junction.zip could not create junction.exe acces denied
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 01:28:21 AM
Hi darkmata,

Run a new scan with with TDSSKiller and remove anything that it finds.  Then post the logs that are made.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 08:28:47 AM
Hi jeffce

no threats found with TDSSKILLER, here is the log.

thanks
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 12:53:57 PM
Hi darkmata,

This one is fighting LOL!!  :D
--------

Download GMER Rootkit Scanner from here (http://www.gmer.net/gmer.zip) or here (http://www.majorgeeks.com/download.php?det=5198).

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
.
----------
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 01:11:49 PM
Hi jeffce,

i cannot check/uncheck the ones that you tell me because they appear unusable (on grey) i can only check/unchek services, registry, files, the partitions, ADS and show all.

do i continue? and just uncheck the show all one and the partition that is not C:?
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 01:15:06 PM
Hi,

Yes just be sure that Show All and C: is not checked.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 01:21:15 PM
Hi jeffce,

yeah this one is fighting! i usually play on-line fps and since i have this i'm always lagging as hell, but my ping to server is just between 15 and 40 ms.. ???

well i don't know if it helps in any way, but...

here is the file.

thanks
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 01:32:20 PM
Ok...

Reboot Your System in Safe Mode

Once in Safe Mode try to run a scan with ComboFix again.  If the log is created please post that. 
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 01:42:41 PM
Hi jeffce,

no file created... :'( same issue as always not even able to close the combofix window it disappears....and 10 sec. later a blue screen with an error and dumping memory... :(

grrr...

thanks!
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 01:48:06 PM
i have .zip with the suposed virus files, that avast technical support asked me to do so, and send them, do you want it?

thanks for all of your work !
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 02:15:38 PM
Hi darkmata,

Sure go ahead and send that file and let's see what we have.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 02:21:55 PM
Hi jeffce,

i renamed it on.txt i supose that just changing it to .zip will work

thanks.
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 02:59:31 PM
Hi,

Just attach the .zip file :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 03:02:39 PM
i try but it says me .zip not valid file to send here
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 03:11:04 PM
Upload it to mediafire.com found >> http://www.mediafire.com/

Post the link created so I can retrieve it.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 03:14:35 PM
Hi jeffce,

here it is:

http://www.mediafire.com/file/d9pprmzcz7r49sp/Virus.zip

thanks.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 04:04:16 PM
lol i just putted there 2 files, now they are a lot!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 07:17:30 PM
Hi darkmata,

Run a new scan with aswMBR and post the new log so I can have a look at that.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 08:07:20 PM
Hi jeffce, 
sorry wasn't at pc, here you are.
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 08:11:12 PM
Hi darkmata,

Thank you.  :)

Please double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".

(http://i1190.photobucket.com/albums/z454/Blottedisk/aswMBRfix-1.png) (http://i1190.photobucket.com/albums/z454/Blottedisk/aswMBRfix.png)
Click the image to enlarge it
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 08:42:49 PM
Here is the log
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 09:07:37 PM
Ok good job...

Delete all copies of ComboFix then....

Download Combofix from either of the links below, and save it to your desktop. 
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

**Note:  It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://"http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216")

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 09:22:40 PM
Hi jeffce,

sad to say that , but same as always....
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 09:25:23 PM
Hi,

Ok let me do some digging and I will get back as soon as I can.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 09:25:55 PM
ok thanks!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 14, 2012, 09:46:54 PM
Hi,

For x64 bit systems download Farbar Recovery Scan Tool x64 (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
[/list]
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 14, 2012, 10:09:32 PM
here we go!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 01:50:28 PM
Hi darkmata,

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

Code: [Select]
SubSystems: [Windows] ==> ZeroAccess
C:\Windows\system32\consrv.dll
2 pinger; C:\Windows\System32\flashcom.dll [5120 2009-07-14] (Iomega)
C:\Windows\System32\flashcom.dll
3 MEMSWEEP2; \??\C:\Windows\system32\171F.tmp [x]
C:\Windows\system32\171F.tmp
2012-03-13 13:30 - 2012-03-14 20:41 - 0000000 __ASH C:\Windows\System32\dds_log_ad13.cmd

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system[/color]

On Vista or Windows 7: Now please enter System Recovery Options.
Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ...
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 02:05:34 PM
Hi jeffce,

here is the log :)

Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 03:15:53 PM
Hi,

LOL!!  Great avatar pic!!  hahahaha!!  :D
----------

Ok....lets give this another shot and see what we can do.

Delete all copies of ComboFix from your system.

Next

Download Combofix from either of the links below, and save it to your desktop. 
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

**Note:  It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://"http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216")

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 03:31:26 PM
LOL, uah, dark +dalmata.. ;D
Answering from the phone Combofix working-class for first time..
 ::) ;D
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 03:44:05 PM
Hi jeffce
Answering from phone again now i cannot execute anything ,wanted to open FireFox to answer you but error
Attempt to ilegal operation on a regitsry key that was checked for its elimination, sale with explorer and everything else.... :-\
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 03:44:47 PM
Just reboot your system.  If it still happens after reboot, do it again.  That should fix it.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 03:47:38 PM
Oh yeah!

 ;D ;D ;D
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 03:52:11 PM
Oh yeah!!  :D

That knocked it in the head. 

Please run a new scan with OTL
In Custom Scans put the following:
netsvc
/md5start
consrv.dll
/md5stop
createrestorpoint

Press Run Scan and post the newly made log. 
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 03:58:43 PM
You are a MASTER  8)

here is the log

THAAANK YYOOUU!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 04:10:55 PM
Hi,

Run OTL.exe
Code: [Select]
:Services

:OTL
[2012/03/10 10:59:52 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{2EEA20C8-39EB-453B-9D2A-8D364CB105A9}
[2012/03/10 10:59:38 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{C0E6E625-AF36-4C80-9AAB-DB2FA7C924E2}
[2012/03/09 17:29:53 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{A9765B12-ABBD-438E-AB7B-9D486293A0EE}
[2012/03/09 17:29:42 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{18CCC289-B64F-4552-8E70-27B97944F5B6}
[2012/03/07 19:20:19 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{E793880A-BF52-4997-A09C-370B37BBE9AE}
[2012/03/07 19:20:09 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{09B93BFB-6E6A-43A4-A66E-5F76AFC729FD}
[2012/03/07 16:13:36 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{7F905CD3-AAB5-4A37-8A24-2AC8D8F817AD}
[2012/03/06 08:04:48 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{74CC19AC-6896-4BA1-9396-A559D12BC32D}
[2012/03/06 08:04:36 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{4C1CBED5-F790-4C25-B6F8-B18B6FCA6C67}
[2012/03/04 10:26:45 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{945A7F46-2F88-4270-B0E6-52D62C7340C4}
[2012/03/04 10:26:35 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{6C7A532A-90F1-42BD-AE1C-70CD1283CC2B}
[2012/03/03 10:18:10 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{30A9416E-2529-4370-A279-D433C35253B6}
[2012/03/03 10:17:59 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{761EF695-D1CC-4711-BB5E-4F01B1A39A9E}
[2012/03/02 07:21:40 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{6CB52A50-8ADD-4B4A-BB7F-91967E6FDDD6}
[2012/03/02 07:21:28 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{91FA6030-8D6C-466F-BE63-DE1318CD1AE6}
[2012/03/01 18:08:30 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{28A3D943-2D3A-4888-AEA8-DD98CB1FE89D}
[2012/03/01 18:08:20 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{71E9D2C3-BE6C-4C9F-A60E-48CC5CEF90AA}
[2012/03/01 17:25:16 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{EB3228DA-9CE5-40C7-84F9-6C6CD44AD946}
[2012/03/02 07:21:40 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{6CB52A50-8ADD-4B4A-BB7F-91967E6FDDD6}
[2012/03/02 07:21:28 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{91FA6030-8D6C-466F-BE63-DE1318CD1AE6}
[2012/03/01 18:08:30 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{28A3D943-2D3A-4888-AEA8-DD98CB1FE89D}
[2012/03/01 18:08:20 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{71E9D2C3-BE6C-4C9F-A60E-48CC5CEF90AA}
[2012/03/01 17:25:16 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{EB3228DA-9CE5-40C7-84F9-6C6CD44AD946}
[2012/02/28 17:34:47 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{829ECCA7-2ADA-4783-BC5C-A5EB5C4D621B}
[2012/02/28 17:34:34 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{E7485E0E-ADF7-4B00-8F30-BA4225D3B326}
[2012/02/27 16:52:51 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{1E47C8D2-815C-40C5-97F9-778BD64C5416}
[2012/02/27 16:52:41 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{9392265D-C1CC-4F8C-B167-F4FBB986EC0B}
[2012/02/25 08:49:17 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{9270C156-3AD2-44AA-A38E-F9098F2B8C6B}
[2012/02/24 17:11:25 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{33611E4E-7732-42A7-9DFC-4686BABBA81C}
[2012/02/24 17:11:12 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{826047E8-2689-4EF4-8F77-C3EBF66F14F4}
[2012/02/23 21:34:17 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{814B6225-B0D6-437B-9605-AE179A0A3CA2}
[2012/02/23 21:34:06 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{406357EC-F76F-4CC8-BB80-C7646B0A6384}
[2012/02/22 15:01:12 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{CE10A3BB-70B5-42C2-8C8C-79637018083D}
[2012/02/21 07:37:14 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{39989B8B-C12F-4D51-8516-96007EF949B1}
[2012/02/21 07:37:02 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{271B9FEA-7BA1-4431-AF38-24C2DE79B8D8}
[2012/02/20 18:02:25 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{D82808C5-BCAC-4AEC-B24C-2D364DB0A15A}
[2012/02/19 19:12:02 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{8F5D34A4-B477-4E7B-9E1F-0D1ABE45A9B1}
[2012/02/19 19:11:51 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{7D66D353-F098-4FFE-9DE3-7F5CFE5D8702}
[2012/02/19 12:05:12 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{2E2FF5A0-18C2-4806-9986-E91812C0F0F1}
[2012/02/19 12:05:02 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{AD7B2EA4-D711-46FA-AF23-8F63654F4DA7}
[2012/02/18 10:44:46 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{4511EB5A-575B-4BB3-8276-3F530276C50D}
[2012/02/18 10:44:31 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{4F7DE1B5-BF02-4FEB-B992-EB7A81C8688E}
[2012/02/17 16:27:43 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{C6DA5B47-493C-4B47-A2B4-4C4C5E78ACCD}
[2012/02/17 16:27:27 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{C55B1E1A-B4D6-4C43-8C37-395853334083}
[2012/02/16 18:46:26 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{CDD4F407-0982-4D64-8D0E-99DA9DA85D0A}
[2012/02/16 18:46:15 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{0D757FCC-B815-49ED-AB8B-374111FD15E5}
[2012/02/15 08:04:40 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{F5239709-1D47-44DC-82C9-3B45F0EABC60}
[2012/02/15 08:04:28 | 000,000,000 | ---D | C] -- C:\Users\Cure\AppData\Local\{0694624D-62A9-4E1C-9439-199A7DB96E19}

:Files
dir C:\Users\Cure\AppData\Local\cf5171c8 /s /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
netsvcs
/md5start
consrv.dll
/md5stop
createrestorepoint


Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 04:15:14 PM
Hi jeffce

here is the log
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 04:17:53 PM
forget the one before didn't do the scan
i'll do it now sry.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 04:23:29 PM
here we go!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 04:34:46 PM
Malwarebytes

I see that you have Malwarebytes already on your computer.  Please open Malwarebytes, update it and then run a Quick Scan.  Save the log that is created for your next reply.
----------

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
ESET OnlineScan (http://eset.com/onlinescan)
http://www.eset.com/onlinescan/
----------

In your next reply please post the logs created by Malwarebytes and ESET online scanner. 
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 05:45:44 PM
LOL! yes it takes a little time...almost an hour :)

here are the logs

thanks
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 05:47:03 PM
LOOL ;D
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 05:52:27 PM
Hi,

Yep ESET can take some time but it is thorough. 

Those logs look good.  How is your system running now?  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 05:53:06 PM
looks great cristal clear!
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 05:55:35 PM
i'm not redirected no webs.
i don't have any alert message when i use anything on java.
Later i'll try connection on gaming if it still have this connections breaks and lags.

So, that's ready to flow?
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 05:56:18 PM
Good to hear....let's get some updates and one more look at your system.

Please download JavaRa (http://raproducts.org/click/click.php?id=1) to your desktop and unzip it to its own
folder
    click Remove Older Versions.
----------

Run another scan with OTL and post the new log. 

Let me know what malware related problems you have left.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 06:07:50 PM
Hi jeffce

here is the report

How does it look like Doc? :)

Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 06:12:11 PM
Hi darkmata,

Providing there are no other malware related problems...

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D  SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees.  As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
----------

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run  and copy/paste the following text into the Run box as shown and click OK.
  Combofix /Uninstall
  (Note: There is a space between the ..X and the /U that needs to be there.)

(http://i1224.photobucket.com/albums/ee380/jeffce74/CF.jpg)
----------

Clean up with OTL:
----------

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
2. Enable Protected Mode in Internet Explorer.  This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code.  To make sure this is running follow these steps:3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly.  A tutorial on firewalls can be found here (http://www.bleepingcomputer.com/forums/tutorial60.html).  **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free (http://download.cnet.com/Online-Armor-Free/3000-10435_4-10426782.html)
Agnitum Outpost Firewall Free (http://download.cnet.com/Agnitum-Outpost-Firewall-Free/3000-10435_4-10913746.html)

5. Make sure you keep your Windows OS currentWindows XP users can visit Windows update  (http://v4.windowsupdate.microsoft.com/en/default.asp)  regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.  Without these you are leaving the back door open.

6. Consider a custom hosts file such as MVPS HOSTS (http://www.mvps.org/winhelp2002/hosts.htm). This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.  For information on how to download and install, please read this tutorial by WinHelp2002 (http://"http://www.mvps.org/winhelp2002/hosts.htm")
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7.   WOT   (http://www.mywot.com/) (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites.  WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?  (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
 
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 15, 2012, 06:30:16 PM
Hi jeffce, done it all, but i never use internet explorer always firefox, shall i do it as well?

so i'll try now to install the AV i got from avast!and let's see what happens.

more questions: :)
Can i hide all the files and so..?
Do i have to have Avast! internet security and MBAM as well(i mean pro)?

And where do i have to send the bottle of wine? 8)

thanks and good job!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 15, 2012, 07:23:12 PM
Hi darkmata,

You should always keep Internet Explorer up-to-date because that is the browser the Windows uses to perform all it's updates by default.
----------

I do run both Avast and MBAM Pro at the same myself so I would recommend it.  :)
----------

I hope that answered your questions.  :)
Title: Re: infected with sirefef-ZEROACCESS
Post by: darkmata on March 16, 2012, 10:04:13 AM
Hi jeffce!

just wanted to let you know that my sytem is now running smooth as silk...lol

thanks so much again!
Title: Re: infected with sirefef-ZEROACCESS
Post by: jeffce on March 16, 2012, 12:46:13 PM
Hi darkmata,

You are more than welcome!  I am glad I could help.  :)