Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
need some help with removing trojan win64\sirefef.y
« previous
next »
Print
Pages:
1
2
[
3
]
4
5
...
9
Go Down
Author
Topic: need some help with removing trojan win64\sirefef.y (Read 38818 times)
0 Members and 1 Guest are viewing this topic.
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #30 on:
June 18, 2012, 10:56:37 PM »
I tried, MSE still tries.
Logged
essexboy
Malware removal instructor
Avast Überevangelist
Probably Bot
Posts: 40589
Dragons by Sasha
Re: need some help with removing trojan win64\sirefef.y
«
Reply #31 on:
June 18, 2012, 10:59:27 PM »
OK there are options that you could try
Either use FRST and read the log
Let me know if there are any references to ZA or Zero Access
Or from the recovery console select to system restore prior to the malware infection
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #32 on:
June 18, 2012, 11:02:44 PM »
I think the ZA first installed itself in January, according to the directory, which couldn't be deleted, but I eventually did. it was under c:\windows\installer\ called {0d5f61ab-623a-4f10-8749-5309355bb099}.
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #33 on:
June 18, 2012, 11:11:58 PM »
or call it a day, and I'll have a flash drive tomorrow, so I could post the OTL logs, and continue from Reatogo.
Logged
essexboy
Malware removal instructor
Avast Überevangelist
Probably Bot
Posts: 40589
Dragons by Sasha
Re: need some help with removing trojan win64\sirefef.y
«
Reply #34 on:
June 18, 2012, 11:14:02 PM »
OK run OTLPE
look down the log and you will see entries similar to c:\windows\installer\{0d5f61ab-623a-4f10-8749-5309355bb099}
Also check this area
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=
winsrv
:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
If the red element is consrv then put that line in its entirety there as well in this format
:OTL
O38 - SubSystems\\Windows: (ServerDll=
winsrv
:ConServerDllInitialization,2)
If so in the OTLPE Custom scans and fixes box copy the folder path only as we will delete it in its entirety
like so :
:Files
c:\windows\installer\{0d5f61ab-623a-4f10-8749-5309355bb099}
Similar to this one
http://forum.avast.com/index.php?topic=99747.0
Once you have entered it into the box, press run Fix
On completion try to boot back to windows
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #35 on:
June 18, 2012, 11:22:25 PM »
Microsoft Safety Scanner actually deleted some items before (a few days ago), and I was able to manually delete this folder in installer\. should I still check for this line?
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #36 on:
June 18, 2012, 11:30:47 PM »
I'm going go look for that line, then call it a day. I'll be back same time tomorrow, with flash drive, and will continue from that point.
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #37 on:
June 18, 2012, 11:33:36 PM »
I searched for winsrv, consrv, and that 0d5f61ab... and nothing found. I'll have a flash drive tomorrow, I'll be here same time, will post OTL, and those 2 other logs.
thanks for your help today.
Logged
essexboy
Malware removal instructor
Avast Überevangelist
Probably Bot
Posts: 40589
Dragons by Sasha
Re: need some help with removing trojan win64\sirefef.y
«
Reply #38 on:
June 18, 2012, 11:45:08 PM »
If you use the flash drive then FRST will be the best option... Talking to OT he has not yet updated OTLPE to the latest version
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #39 on:
June 19, 2012, 05:41:57 PM »
ok. got the flash drive. more than enough space. MSE finds Trojan Win64 Win64/Sirefef.Y. and it says System32 Services.exe C:\windows\sys32\services.exe->731.
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #40 on:
June 19, 2012, 05:57:14 PM »
copied FRST64.exe over. it says not a valid win32 application when I try to run it from the flash drive.
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #41 on:
June 19, 2012, 06:03:54 PM »
I'm going ahead with USB option, WinToBootic.
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #42 on:
June 19, 2012, 06:29:27 PM »
yeah, C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess, then it says ATTENTION!
Logged
cool_gecko
Guest
Re: need some help with removing trojan win64\sirefef.y
«
Reply #43 on:
June 19, 2012, 06:54:03 PM »
found this:
http://www.doitscared.com/1259/recover-from-the-sirefef-y-virus-infection/
(checked comments, and used vt, the file(s) are clean)
Logged
essexboy
Malware removal instructor
Avast Überevangelist
Probably Bot
Posts: 40589
Dragons by Sasha
Re: need some help with removing trojan win64\sirefef.y
«
Reply #44 on:
June 19, 2012, 07:06:53 PM »
OK if you could post the FRST log I will craft a fix for you
Logged
Print
Pages:
1
2
[
3
]
4
5
...
9
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
need some help with removing trojan win64\sirefef.y