Reply
Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

Found any other .txt logs for Combofix due to previous runs and the quarantine txt are in the folder  C:\Qoobox don't touch the other folders inside that folder.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

The log is attached.

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

The two text files in C:\Qoobox are attached.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

That's a little different

 

Download  http://www.pandasecurity.com/enterprise/support/card?id=1672&idIdioma=2

 

Disable Norton then run the tool.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

The panda tool just finished.

 

Computer is slowing down quite a bit, and startup and shutdown sounds are coming out garbled. How risky is it to keep my computer on for so long? Would I have a better chance of saving it if I just shut it down now and hired a professional in my area to work on it?

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

Where is the Panda log.

 

the slow down could be because it's trying to find drivers and services that no longer exist, so as that takes resources  and everything else slows down including making sounds etc.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Here is the panda log.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

[ Edited ]

It found the files,  

 

 

MD5's  

 

B89CFBE8CB247B57D8C10ADAA66B462B  https://www.virustotal.com/file/458b56bbbd3cd478e04390ed5ffd08ca4f3709b37851e64cd9eacb2f749dfbf4/ana...s/

 

MD5 11028C6A84A967070CB1286550F2058F https://www.virustotal.com/file/eeaeb1506d805271b5147ce911df9c264d63e4d229de4464ef879a83fb225a40/ana...

 

 

Remember you also had or have other program and tool leftovers and maybe it has hurt the netsvcs in the registry to be fixed later if that is so.

 

You can turn off the PC when you want to as the rootkit appears broken, just some clean up steps to do and checks.  I will have to create a script.

 

Also these tools do take up resouce during the reboot and runnong process as they battle and search for what they need to.

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

 Read all of this message first

 

Download Combofix http://www.bleepingcomputer.com/download/anti-virus/combofix


  • Ensure that Combofix is saved directly to the Desktop <--- Very important

  • Disable all security programs as they will have a negative effect on Combofix,
  • Close any open browsers and any other programs you might have running before running Combofix 

Doiwnload the attached CFscript.txt, , For some browsers Right Click the attachment on the forum and select "Save AS" or similar to Download it. See screenshot below.

 

Right Click download.jpg

 

Now  drag the CFScript.txt into the ComboFix.exe  

 


  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

*EXTRA NOTES*

  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Stepped away from the computer for a second while ComboFix was running and when I returned the screen was black. It remained black for over 20 minutes, at which time I powered off and powered on again.

 

No ComboFix log, but there is a "My Computer" icon/link labeled ComboFix on C:\.

 

Should I run it again?