Hello,
Seems like I have the Sirefef.AH and Sirefef.R infection. I had tried a bunch of different tools and MSE and MalwareBytes but nothing seems to work. I have Windows 7 Professional.
Any help will be GREATLY appreciated. I am losing my minddd.
I ran the FRST and this it the log results:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-07-2012
Ran by SYSTEM at 08-07-2012 10:52:07
Running from H:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-11-09] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Abhi\...\Run: [googletalk] C:\Users\Abhi\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKU\Abhi\...\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent [1242448 2012-01-21] (Valve Corporation)
HKU\Abhi\...\Run: [Google Update] "C:\Users\Abhi\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-08-31] (Google Inc.)
HKU\Mcx1-ABHI-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [313344 2009-07-13] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
Startup: C:\Users\Abhi\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AMD External Events Utility; C:\Windows\System32\atiesrxx.exe [176128 2011-11-09] (AMD)
2 AppHostSvc; C:\Windows\system32\inetsrv\apphostsvc.dll [61440 2010-11-20] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateServiceV4; "C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" [13672 2011-08-25] (Intuit Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
3 WAS; C:\Windows\system32\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [8913920 2011-11-09] (Advanced Micro Devices, Inc.)
3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [8913920 2011-11-09] (Advanced Micro Devices, Inc.)
0 FixZeroAccess; C:\Windows\System32\drivers\FixZeroAccess.sys [35752 2012-07-08] (Symantec Corporation)
3 MFE_RR; \??\C:\Users\Abhi\AppData\Local\Temp\mfe_rr.sys [16960 2012-07-08] (McAfee, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MSHUSBVideo; C:\Windows\System32\Drivers\nx6000.sys [30576 2010-01-28] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [311296 2009-07-13] (Marvell)
3 SirefefRemover; \??\C:\Users\Abhi\AppData\Local\Temp\b3cf8ee8.tmp [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
[edited by Broni]
ZeroAccess:
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\@
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\n
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\U
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\00000004.@
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\1afb2d56
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\201d3dde
ZeroAccess:
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\@
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\L
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 4095.05 MB
Available physical RAM: 3625.29 MB
Total Pagefile: 4093.32 MB
Available Pagefile: 3626.98 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:195.31 GB) (Free:49.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: () (Fixed) (Total:97.66 GB) (Free:1.37 GB) NTFS
4 Drive e: () (Fixed) (Total:274.94 GB) (Free:18.4 GB) NTFS
5 Drive f: (New Volume) (Fixed) (Total:400.86 GB) (Free:38.01 GB) NTFS
6 Drive g: (Rojith0557850123) (CDROM) (Total:1.87 GB) (Free:0 GB) CDFS
7 Drive h: () (Removable) (Total:15.38 GB) (Free:7.53 GB) FAT32
8 Drive t: (New Volume) (Fixed) (Total:931.51 GB) (Free:102.41 GB) NTFS
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 1024 KB
Disk 1 Online 372 GB 7168 KB
Disk 2 Online 931 GB 0 B *
Disk 3 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 195 GB 31 KB
Partition 2 Primary 400 GB 195 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 195 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F New Volume NTFS Partition 400 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 0 Extended 372 GB 8032 KB
Partition 1 Logical 97 GB 8064 KB
Partition 2 Logical 274 GB 97 GB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 97 GB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E NTFS Partition 274 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Dynamic Data 931 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 42
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 T New Volume NTFS Simple 931 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 15 GB 0 B
==================================================================================
Disk: 3
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-06-28 16:06
======================= End Of Log ==========================
Seems like I have the Sirefef.AH and Sirefef.R infection. I had tried a bunch of different tools and MSE and MalwareBytes but nothing seems to work. I have Windows 7 Professional.
Any help will be GREATLY appreciated. I am losing my minddd.
I ran the FRST and this it the log results:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-07-2012
Ran by SYSTEM at 08-07-2012 10:52:07
Running from H:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-11-09] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Abhi\...\Run: [googletalk] C:\Users\Abhi\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKU\Abhi\...\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent [1242448 2012-01-21] (Valve Corporation)
HKU\Abhi\...\Run: [Google Update] "C:\Users\Abhi\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-08-31] (Google Inc.)
HKU\Mcx1-ABHI-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [313344 2009-07-13] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
Startup: C:\Users\Abhi\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AMD External Events Utility; C:\Windows\System32\atiesrxx.exe [176128 2011-11-09] (AMD)
2 AppHostSvc; C:\Windows\system32\inetsrv\apphostsvc.dll [61440 2010-11-20] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateServiceV4; "C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" [13672 2011-08-25] (Intuit Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
3 WAS; C:\Windows\system32\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [8913920 2011-11-09] (Advanced Micro Devices, Inc.)
3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [8913920 2011-11-09] (Advanced Micro Devices, Inc.)
0 FixZeroAccess; C:\Windows\System32\drivers\FixZeroAccess.sys [35752 2012-07-08] (Symantec Corporation)
3 MFE_RR; \??\C:\Users\Abhi\AppData\Local\Temp\mfe_rr.sys [16960 2012-07-08] (McAfee, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MSHUSBVideo; C:\Windows\System32\Drivers\nx6000.sys [30576 2010-01-28] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [311296 2009-07-13] (Marvell)
3 SirefefRemover; \??\C:\Users\Abhi\AppData\Local\Temp\b3cf8ee8.tmp [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
[edited by Broni]
ZeroAccess:
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\@
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\n
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\U
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\00000004.@
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\1afb2d56
C:\Windows\Installer\{645c0439-2d19-764c-3c8a-55cecce02c93}\L\201d3dde
ZeroAccess:
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\@
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\L
C:\Users\Abhi\AppData\Local\{645c0439-2d19-764c-3c8a-55cecce02c93}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 4095.05 MB
Available physical RAM: 3625.29 MB
Total Pagefile: 4093.32 MB
Available Pagefile: 3626.98 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:195.31 GB) (Free:49.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: () (Fixed) (Total:97.66 GB) (Free:1.37 GB) NTFS
4 Drive e: () (Fixed) (Total:274.94 GB) (Free:18.4 GB) NTFS
5 Drive f: (New Volume) (Fixed) (Total:400.86 GB) (Free:38.01 GB) NTFS
6 Drive g: (Rojith0557850123) (CDROM) (Total:1.87 GB) (Free:0 GB) CDFS
7 Drive h: () (Removable) (Total:15.38 GB) (Free:7.53 GB) FAT32
8 Drive t: (New Volume) (Fixed) (Total:931.51 GB) (Free:102.41 GB) NTFS
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 1024 KB
Disk 1 Online 372 GB 7168 KB
Disk 2 Online 931 GB 0 B *
Disk 3 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 195 GB 31 KB
Partition 2 Primary 400 GB 195 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 195 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F New Volume NTFS Partition 400 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 0 Extended 372 GB 8032 KB
Partition 1 Logical 97 GB 8064 KB
Partition 2 Logical 274 GB 97 GB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 97 GB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E NTFS Partition 274 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Dynamic Data 931 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 42
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 T New Volume NTFS Simple 931 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 15 GB 0 B
==================================================================================
Disk: 3
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-06-28 16:06
======================= End Of Log ==========================