Author Topic: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef  (Read 4646 times)

0 Members and 1 Guest are viewing this topic.

Ever_After

  • Guest
Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« on: July 25, 2012, 04:26:25 AM »
Hi, I keep getting pop-ups telling me that a malware or threat have been detected. Avast pop-ups say that they were moved to the virus chest. The infections that keep coming up are Win 32 Malware Gen, Win 32 Downloader pKU (Trj), and Win 64 Sirefef-A. I have never had this problem before and I'm new here. What should I do? Please help!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #1 on: July 25, 2012, 07:20:53 AM »
follow the guide and attch...not copy and paste.....logs from malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

Ever_After

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #2 on: July 25, 2012, 10:53:17 AM »
I've been able to run the malwarebtyes program and got the log for it, but I am having trouble running the OTL program. It has froze three times and wasn't responding. I waited more than 20 minutes each time and nothing happened. I restarted my laptop after the second time and the same thing happened. Should I just wait until it responds? I don't mind doing, that but is this normal? What should I do?
« Last Edit: July 25, 2012, 11:12:31 AM by Ever_After »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #3 on: July 25, 2012, 11:26:00 AM »
continue with aswMBR

then the malware remover will find a way to run OTL

Ever_After

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #4 on: July 25, 2012, 12:05:36 PM »
Here is the malwarebytes log.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #5 on: July 25, 2012, 12:22:01 PM »
as you can see in your mbam log all the PUP detections are not marked for removal.....and as they all seems to be some toolbar adware stuff, i recomend you do a new quick scan...and then mark them all for removal, befor you hit the "remove selected" button

SafeSurf

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #6 on: July 25, 2012, 12:28:50 PM »
I noticed that too in the OP's MBAM scan.  Make sure you update MBAM prior to scanning again.

Ever_After

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #7 on: July 25, 2012, 12:54:22 PM »
Okay, I thought I had removed everything by clicking the "remove selected" button the first time. I'll go ahead and do that, but how do I update MBAM? My computer suddenly shut down while running aswMBR because the pop up threats kept appearing. I'm afraid my computer is getting worse, so I've shut it down for now and will start to do this in a few hours.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #8 on: July 25, 2012, 01:19:11 PM »
when you open MBAM you see a update tab at the top

Ever_After

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #9 on: July 26, 2012, 01:48:31 AM »
I removed all of the PUP detections and have began scanning with the aswMBR program. Is this scan supposed to take a longer than the Malwarebytes scan? It seems to have stopped and it says it is still scanning, but I don't see anything moving. It's almost going to be an hour. I noticed that it found something infected four minutes before it stopped. I don't know if that has anything to do with it. I don't mind waiting if this is normal, but I really want to move on to the next step asap. Thank you for the help!
« Last Edit: July 26, 2012, 02:25:39 AM by Ever_After »

Ever_After

  • Guest
Re: Win 32 Downloader PKU, Win 32 Malware Gen, Win 64 Sirefef
« Reply #10 on: July 27, 2012, 04:52:54 AM »
I've attached part of my aswMBR log. It didn't successfully scan the first time even though I waited 4 hours. I'm not sure if it will be helpful, but I'm trying to run a scan again. It seems to have stopped, but I will leave it to see if it scans successfully this time. I don't know if the wait time for the aswMBR scan is supposed to take this long. Can someone please help?