Author Topic: need some help with removing trojan win64\sirefef.y  (Read 37576 times)

0 Members and 1 Guest are viewing this topic.

cool_gecko

  • Guest
need some help with removing trojan win64\sirefef.y
« on: June 18, 2012, 05:20:55 AM »
hi, been lurking here for a while, so I know you guys are good at removing tough malware. have a computer that's been infected with ZeroAccess. I will be at the client's location in about 12 hours, I could post logs then. MBAM originally found ZeroAccess, and removed it, but it's back after reboot. Microsoft Safety Scanner removed 2 additional trojans, and partly removed sirefef.y, then a message appears saying some critical error, and will reboot in a minute, please save your work. Currently, the computer has MSE installed (which is better than the previous av). I've been told by client that MSE finds it at bootup, and then goes into a boot loop.

TIA

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: need some help with removing trojan win64\sirefef.y
« Reply #1 on: June 18, 2012, 06:10:13 AM »
follow the guide here and attach (not copy and paste) logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0


when done a malware removal specialist will be notified......and help you when he arrive....may take several hours

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #2 on: June 18, 2012, 04:05:59 PM »
Monitoring

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #3 on: June 18, 2012, 05:27:11 PM »
at windows 7 bootup, everything is fine, then MSE (only temp AV) finds it, and says cleaning. then it pops up saying system has a critical error and has to reboot in 1 min, so I can't disable MSE, or do anything, including running those tools.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: need some help with removing trojan win64\sirefef.y
« Reply #4 on: June 18, 2012, 05:29:28 PM »
at windows 7 bootup, everything is fine, then MSE (only temp AV) finds it, and says cleaning. then it pops up saying system has a critical error and has to reboot in 1 min, so I can't disable MSE, or do anything, including running those tools.

Does safe mode work..??
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #5 on: June 18, 2012, 05:30:51 PM »
tried. same thing.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: need some help with removing trojan win64\sirefef.y
« Reply #6 on: June 18, 2012, 05:32:23 PM »
tried. same thing.

Better wait for Essexboy then.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #7 on: June 18, 2012, 07:33:54 PM »
      OK can you burn a cd or if you have windows 7 then a USB will do.  I will give instructions for both

CD- XP/Vista

Please print these instruction out so that you know what you are doing

  • Download OTLPENet.exe to your desktop
  • Download Farbar Recovery Scan Tool and save it to a flash drive.
  • Ensure that you have a blank CD in the drive
  • Double click OTLPENet.exe and this will then open imgburn  to burn the file to CD
  • Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads  :)
  • Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
  • Insert the flash drive with FRST on it
  • Locate the flash drive and run FSRT
  • The tool will start to run.

  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
[/list]


USB

Download the following three programmes to your desktop :

1.  WiNToBootic
2.  Windows 7 64bit RC
     Windows 7 32bit RC
3.  64 bitFarbar Recovery Scan Tool x64
     32 bitFarbar Recovery Scan Tool

Extract wintoboot to your desktop
Insert a USB drive of at least 4GB
Run Wintoboot



Drag and drop the Windows 7 ISO to the programme in the space indicated
Tick the Format box and accept the warnings
Press Do It

You will see it progressing



It will let you know when it is done
Then copy FRST to the same USB




Insert the USB into the sick computer and start the computer.  First ensuring that the system is set to boot from USB
Note: If you are not sure how to do that follow the instructions Here

 
When you reboot you will  see this although yours will say windows 7. Click repair my computer

 
Select your operating system

 
Select Command prompt

 
At the command prompt type the following  :

notepad and press Enter.
The notepad opens. Under File menu select Open.
Select "Computer" and find your flash drive letter and close the notepad.
In the command window type e:\frst64.exe and press Enter
Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list]

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #8 on: June 18, 2012, 07:59:36 PM »
I'm following the CD instructions, since I don't have a flash drive with me. Currently downloading OTLPENet on working pc. it says to download FRST to flash drive. should I download that to CD too? also, this is Win7 x64, so I should download the x64 FRST from the 2nd instructions?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #9 on: June 18, 2012, 08:32:34 PM »
If this is win 7 64 bit, it may be worthwhile downloading the boot disc as that will always come in handy.. I have a copy of that and the 32 bit one

You can put FRST64 on the CD but after OTLPE has been installed - drop it on the root sector 

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #10 on: June 18, 2012, 08:48:58 PM »
done with the install on the CD (OTLPE), but there's not enough room on the CD for FRST64. It's a CD-RW disc.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #11 on: June 18, 2012, 08:58:01 PM »
OK as it stands then Run OTLPE and I will work from that initially

OTLPE should enable you access to the internet

  • Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads  :)
  • Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Right click the file and select send to : select the USB drive. 
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #12 on: June 18, 2012, 09:15:59 PM »
ok, after "yes" for remote registry it asks for select user profile with choices like LocalService, 1 username, etc. and this dialog box has automatically load all remaining users checked. should I select LocalService (top, already selected choice), or username?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #13 on: June 18, 2012, 09:37:17 PM »
Go with local service initially please

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #14 on: June 18, 2012, 09:48:21 PM »
OTL file created, but that pc has no network connection in Reatogo.