Author Topic: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]  (Read 25812 times)

0 Members and 1 Guest are viewing this topic.

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #15 on: December 19, 2011, 02:35:43 AM »
According to avast! I am still infected with this:
C:\Windows\assembly\GAC_32\Desktop.ini      Threat: Win32:Sirefef-FQ [Drp]
 :-[

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #16 on: December 22, 2011, 12:34:08 AM »
...?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #17 on: December 22, 2011, 02:05:07 AM »
It may still be a remnant, but are you getting any of the other symptoms ?

Unfortunately it is 1:05am in the UK so essexboy will be in bed and normally back on the forums after work about 7pm UK time.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #18 on: December 22, 2011, 09:01:40 PM »
Could you re-run an OTL please with the following script

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
C:\Windows\assembly\GAC_32\*.ini
/md5stop
C:\Windows\assembly\tmp\U\*.* /s
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #19 on: December 24, 2011, 08:32:05 AM »
Here is the OTL log.

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #20 on: December 24, 2011, 08:32:52 AM »
Here is the extras log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #21 on: December 24, 2011, 11:35:10 AM »
Hmm that showed one file that should not be there

color=green]Download and Install Combofix[/color]
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #22 on: January 09, 2012, 12:50:48 AM »
Sorry, I was away on holidays and had no access to a computer.
Here is the log from Combofix.

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #23 on: January 18, 2012, 08:51:51 AM »
Help! ???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #24 on: January 18, 2012, 02:42:12 PM »
Because of the delay essexboy may not be subscribed to this topic, I will PM him to notify.

I'm afraid that you may be in for a little time zone ping pong as it 1:42pm in the UK and essexboy may not be back in the forums until later in the day around 7pm.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #25 on: January 18, 2012, 02:45:25 PM »
Hi there are the alerts still occuring ?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #26 on: January 18, 2012, 02:50:49 PM »
Thought you would be at work essexboy ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #27 on: January 18, 2012, 03:16:41 PM »
Nope taking a few days off  ;D

anusmyn

  • Guest
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #28 on: January 20, 2012, 01:59:02 AM »
Scan finds this:
C:\_OTL\MovedFiles\12182011_132538\C_Windows\...Destop.ini Threat Win32:Sirefef-FQ [Drp]

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\Windows\assembly\GAC_32\Desktop.ini Threat: Win32:Sirefef-FQ [Drp]
« Reply #29 on: January 20, 2012, 01:50:43 PM »
That is the OTL quarantined file

Any other problems ?