Author Topic: Win32:Atraps-PF and Win64:Sirefef-A recurring problem  (Read 34311 times)

0 Members and 1 Guest are viewing this topic.

brmeau

  • Guest
Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« on: July 03, 2012, 01:55:54 AM »
The two noted viruses keep recurring after sending them to the chest.  I get a new alert every few minutes.  My system is definitely being affected.  Can you please help?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #1 on: July 03, 2012, 07:49:46 AM »
follow this guide and attach (not copy and paste) the logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0


when done a malware removal specialist will be notified....

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #2 on: July 03, 2012, 02:15:47 PM »
Monitoring...  :)

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #3 on: July 03, 2012, 03:12:13 PM »
Ok..first of all I was not able to access I/E from my icon...some of my icons/programs will not work.  So, I had to do this in Safe Mode.  I hope that this is alright.  I downloaded Malwarebytes successfully and have the MBAM file.

Next problem, after I received the MBAM file it said to reboot in which I did.  When it rebooted normally my screen is now completely blank.  Then I tried to reboot in Safe Mode again and did have a screen with icons.  I went to download the OTL (in safe mode) and it gave me a message to the effect that an .exe file should not normally be downloaded and asked if I wanted to delete or run anyway.  I chose to run anyway and nothing downloaded to my system as the instructions stated..."click on icon, make sure other programs not running, etc.".  The only thing that happened was the OTL menu appeared on my screen but was not saved to my system.

Now what?
Thank you very much.

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #4 on: July 03, 2012, 03:29:10 PM »
Go ahead and attach the log made by Malwarebytes and then do the following (in safe mode with networking if needed)...

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
----------

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #5 on: July 03, 2012, 03:55:06 PM »
I tried to download DDS but had similiar problem as with OTL download.  It ran but would not save to desktop and therefore was not run as Administrator in your instructions.  The resulting files are attached.

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #6 on: July 03, 2012, 04:44:00 PM »
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.  :)
----------

Download Combofix from the link below, and save it to your desktop. 
Link

**Note:  It is important that it is saved directly to your desktop**
 If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the C:\ComboFix.txt for further review.

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #7 on: July 03, 2012, 05:00:05 PM »
First, thank you very much with your help so far!  I went to download Combofix and save it to my desktop (in safe mode) but like the others I am getting a error type message that states..

"The publisher of ComboFix(4).exe couldn't be verified."

Then, I have option to choose "Run" or "View downloads".

Sorry, but I just want to be sure that I choose the right thing.

Also, I do not know if this helps but I do have the original Vista disk that came with this system.

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #8 on: July 03, 2012, 05:06:46 PM »
Go ahead and run it.  :)

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #9 on: July 03, 2012, 05:26:10 PM »
I ran Combofix but I can't seem to find where the .txt file was saved.  It is kind of like the other files that I tried to save and run...could this be because I am running in Safe Mode?  Anyway, it says that it completed it but I can't find the .txt file.

Any thoughts?

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #10 on: July 03, 2012, 05:35:27 PM »
The log is not located at C:\Combofix.txt ? 

If not there look for it in C:\Qoobox\ComboFix.txt

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #11 on: July 03, 2012, 05:40:18 PM »
It is definitely not at C: root directory.  There is a Qoobox directory that was created and it has some folders in it.  I looked through the individual folders but I do not see any .txt files at all.

jeffce

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #12 on: July 03, 2012, 05:59:23 PM »
Ok...go ahead and run ComboFix again and hopefully there is a log created.  If not we may need to try another route.

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #13 on: July 03, 2012, 06:25:35 PM »
I downloaded and reran Combofix.  As I was watching the file process it said that "Output Folder" was 32788R22FWJFW and then my computer beeped several times and an error message displayed but disappeared too quickly to be read.  This time the attached file appeared on drive C:\.

Ok...just tried to attach the file named Combofix but said that I could not open it to attach it and may need Administrator priviledges.

brmeau

  • Guest
Re: Win32:Atraps-PF and Win64:Sirefef-A recurring problem
« Reply #14 on: July 03, 2012, 07:19:09 PM »
I wanted to let you know that I found the OTL file that I had earlier stated would not download to my desktop.  It looks to be on the system but just not accessible from the desktop.  Would you like me to try and run it?