Reply
Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

afd.sys.org is gone.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

YAY!!!!

 

Now for afd.sys.vir, but there is an extra step. just in case

 

Before trying afd.sys.vir and starting GMER  Disable Norton, this is because Norton / Symantec detects the file and SONAR or Auto-Protect may block GMER from deleting.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

All gone!

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

You can easily go and delete the copy you created to send to virus total also,  and from the recycle bin if it goes into there.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Copy of afd.sys.vir sent to recycling bin, and recycling bin emptied!

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

OK 

 

Now Norton and Malwarebytes.   Uninstall Norton and Malwarebytes via the Add / Remove programs in Control Panel.

 

Then for Norton run the Norton Removal Tool twice, Removal tool link for download https://www-secure.symantec.com/norton-support/jsp/help-solutions.jsp?lg=english&ct=united+states&do...

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Just have to reboot after second run of NRT.

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Or wait, apparently no reboot necessary.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Help with ZeroAccess/Sirefef infection

Hopefully the PC is getting faster without all the conflicts and Malware running on the system

 

Run OTL again with the same script etc. as before BUT instead of 180 days, just the standard 30 days will do. for the file age range.

 

Quads

Contributor
jackalbins
Posts: 32
Registered: ‎05-13-2012

Re: Help with ZeroAccess/Sirefef infection

Computer does seem a bit faster. Here is the latest OTL log.