Author Topic: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!  (Read 4207 times)

0 Members and 1 Guest are viewing this topic.

Bwana2000

  • Guest
Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« on: August 14, 2012, 11:02:41 PM »
Hi

Clicked a video link on facebook today which updated my Flash player, as it seemed, but apparently installed nothing but trojans  >:(

Sirefef-AHF and Win32:Malwaregen are getting back no matter how I try to remove them.

I've tried Malwarebytes (didn't find any), SuperAntiSpyware (didn't find any) and Avast. After reading the support forum I realize others have been helped by your great staff so I'm hoping for your assistance as well. I would like to avoid a system restore...

Attaching logs from aswMBR and FSS. I do have from OTL but it is too big (286kB) to upload.

Looking forward to your reply  :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89115
  • No support PMs thanks
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #1 on: August 14, 2012, 11:10:30 PM »
You can use a file sharing site such as Mediafire.com - Upload to http://www.mediafire.com/ and post the sharing link.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37545
  • Not a avast user
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #2 on: August 14, 2012, 11:28:52 PM »
Quote
I've tried Malwarebytes (didn't find any), SuperAntiSpyware (didn't find any)
did you update MBAM and SAS before you scanned ?


anyway, aswMBR say you have Siref and MBAM will not remove that... Essexboy job
« Last Edit: August 14, 2012, 11:31:51 PM by Pondus »

Bwana2000

  • Guest
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #3 on: August 14, 2012, 11:33:52 PM »
Hi,

OTL log is uploaded on http://www.mediafire.com/view/?14xhuncmv6wu2uz

Hmm... SAS was updated but I realize MBAM was not. Updating it now and performing new scan (the teenager did the first scan - I assumed he updated it first but apparently not...)  :P

//Rick

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37545
  • Not a avast user
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #4 on: August 14, 2012, 11:38:04 PM »
tjena grabben ... se mail boxen din

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #5 on: August 14, 2012, 11:52:08 PM »
Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


    Quote
    :Reg
    [HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32]
    ""="%systemroot%\system32\wbem\wbemess.dll"
    [-HKCU\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}]

    :Files
    C:\Windows\Installer\{9c729b61-0b33-b745-702a-58472e0bced4}
    C:\Users\css-mannen\AppData\Local\{9c729b61-0b33-b745-702a-58472e0bced4}
    ipconfig /flushdns /c
    netsh int ip reset c:\resetlog.txt  /c
    ipconfig /release /c
    ipconfig /renew /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

NEXT

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete



Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that

FINALLY

run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Bwana2000

  • Guest
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #6 on: August 15, 2012, 02:03:20 AM »
Hi again,

For now, it seems like this worked! Quiet a process!  ;D

I'm attaching all logs in the post but the OTL's are on Mediafire due to size: http://www.mediafire.com/view/?9vn52xhnw1e6f0m
http://www.mediafire.com/?ca6lu7a4ycb0ldk

Thank you very much for detailed instructions, I'm keeping my fingers crossed everything works now and Trojan is gone! No warnings yet at least  :o

Best regards//Rick

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef-AHF and Win32:Malwaregen can't remove with any tool!
« Reply #7 on: August 15, 2012, 04:55:08 PM »
Right click the link below and select "Save Target As..." to your desktop
https://dl.dropbox.com/u/73555776/bits.reg
Double click the reg file and allow to merge
Reboot

Then let me know what problems remain