Author Topic: Avast found virus but cannot move it to chest  (Read 6127 times)

0 Members and 1 Guest are viewing this topic.

zeens

  • Guest
Avast found virus but cannot move it to chest
« on: January 04, 2013, 02:49:25 AM »
Avast has detected something called win32:sirefef=ZT.   However, it won't let me move it to the chest or delete it.  I keep getting popup messages from Avast about it.  The pop ups say that it has been detected and blocked.  My PC is running slower.  I don't know how to get rid of it.   Thank you.

jeffce

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #1 on: January 04, 2013, 03:12:04 AM »
Hi and welcome!

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
----------

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[SIZE="1"]Click the image to enlarge it[/SIZE]
----------

zeens

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #2 on: January 05, 2013, 07:49:00 PM »
I think I attached all the files.  Thanks again for your help.  I am not a very experienced PC user.   Thank you. 

jeffce

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #3 on: January 05, 2013, 08:51:52 PM »
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.  :)
----------

ComboFix

Download Combofix from the link below, and save it to your desktop. 
Link

**Note:  It is important that it is saved directly to your desktop**
 If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please attach the C:\ComboFix.txt for further review.
----------

zeens

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #4 on: January 06, 2013, 01:37:49 AM »
Thanks for the info.  I may have to be gone for a day or two.  I will think if I want to try the cleaning first.  I will post as soon as I decide.  Pardon my ignorance, but if I choose to just do the reinstall of the operating system, what basically do I have to do?  Can I save my music and files?  Thanks again so much.

jeffce

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #5 on: January 06, 2013, 03:49:22 AM »
Quote
Can I save my music and files?  Thanks again so much.
Yes you are able to save your music, photos, personal files, videos and the like....you will just need to reinstall the operating system and and other software you use.  :)

zeens

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #6 on: January 06, 2013, 11:27:15 PM »
I think instead of cleaning, I will just reinstall the operating system.  Are you able to guide me through how to do that?  Thank you.
« Last Edit: January 07, 2013, 12:53:49 AM by zeens »

jeffce

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #7 on: January 07, 2013, 02:07:40 AM »
Hi,

I am not personally the best at walking someone through reinstalling an operating system, but there is a great site here >> http://forums.whatthetech.com/index.php?showtopic=91962  that can lead you through step-by-step how to do it.  :)

zeens

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #8 on: January 07, 2013, 04:43:13 AM »
My PC has Windows 7.  The receipt says it qualifies for an upgrade discount for Windows 8.  Do you know if I use that, can I use the Windows 8 upgrade and not have the virus?  In other words, instead of reinstaling Windows 7, will this work also? 
I am sorry to be bugging you with all these questions.  I am just trying to figure out the easiest way.  Thank you.




jeffce

  • Guest
Re: Avast found virus but cannot move it to chest
« Reply #9 on: January 07, 2013, 02:00:52 PM »
Quote
Do you know if I use that, can I use the Windows 8 upgrade and not have the virus?
No I would not do that.  If it were my system, I would completely format the system and start over.  If you would like to upgrade to Windows 8 after the system has been formatted I would do that then.  :)