Author Topic: need some help with removing trojan win64\sirefef.y  (Read 37584 times)

0 Members and 1 Guest are viewing this topic.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #30 on: June 18, 2012, 10:56:37 PM »
I tried, MSE still tries.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #31 on: June 18, 2012, 10:59:27 PM »
OK there are options that you could try

Either use FRST and read the log

Let me know if there are any references to ZA or Zero Access

Or from the recovery console select to system restore prior to the malware infection

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #32 on: June 18, 2012, 11:02:44 PM »
I think the ZA first installed itself in January, according to the directory, which couldn't be deleted, but I eventually did. it was under c:\windows\installer\ called {0d5f61ab-623a-4f10-8749-5309355bb099}.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #33 on: June 18, 2012, 11:11:58 PM »
or call it a day, and I'll have a flash drive tomorrow, so I could post the OTL logs, and continue from Reatogo.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #34 on: June 18, 2012, 11:14:02 PM »
OK run OTLPE

look down the log and you will see entries similar to c:\windows\installer\{0d5f61ab-623a-4f10-8749-5309355bb099}
Also check this area

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


If the red element is consrv then put that line in its entirety there as well in this format

:OTL
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)


If so in the OTLPE Custom scans and fixes box copy the folder path only as we will delete it in its entirety

like so :

:Files
 c:\windows\installer\{0d5f61ab-623a-4f10-8749-5309355bb099}


Similar to this one http://forum.avast.com/index.php?topic=99747.0

Once you have entered it into the box, press run Fix
On completion try to boot back to windows

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #35 on: June 18, 2012, 11:22:25 PM »
Microsoft Safety Scanner actually deleted some items before (a few days ago), and I was able to manually delete this folder in installer\. should I still check for this line?

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #36 on: June 18, 2012, 11:30:47 PM »
I'm going go look for that line, then call it a day. I'll be back same time tomorrow, with flash drive, and will continue from that point.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #37 on: June 18, 2012, 11:33:36 PM »
I searched for winsrv, consrv, and that 0d5f61ab... and nothing found. I'll have a flash drive tomorrow, I'll be here same time, will post OTL, and those 2 other logs.

thanks for your help today. :)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #38 on: June 18, 2012, 11:45:08 PM »
If you use the flash drive then FRST will be the best option... Talking to OT he has not yet updated OTLPE to the latest version

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #39 on: June 19, 2012, 05:41:57 PM »
ok. got the flash drive. more than enough space. MSE finds Trojan Win64 Win64/Sirefef.Y. and it says System32 Services.exe C:\windows\sys32\services.exe->731.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #40 on: June 19, 2012, 05:57:14 PM »
copied FRST64.exe over. it says not a valid win32 application when I try to run it from the flash drive.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #41 on: June 19, 2012, 06:03:54 PM »
I'm going ahead with USB option, WinToBootic.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #42 on: June 19, 2012, 06:29:27 PM »
yeah, C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess, then it says ATTENTION!

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #43 on: June 19, 2012, 06:54:03 PM »
found this: http://www.doitscared.com/1259/recover-from-the-sirefef-y-virus-infection/

(checked comments, and used vt, the file(s) are clean)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #44 on: June 19, 2012, 07:06:53 PM »
OK if you could post the FRST log I will craft a fix for you