Advice Regarding Trojans and Further Security

A recent avast quick scan revealed I was infected with the win32: sirefef-WR [Trj] (C:\users.…\AppData\Local\Temp\Win32:sirefef-WR). It was quarantined and I have since deleted it. A full boot scan then revealed I was also infected by Java: Agent-AZV [Trj] (C:\users.…\AppData\Local\Temp\Jar_Cache 879223996810861895.tmpl JM.class). This was then deleted and further scans have said my system is clean.

From things I have read about the Sirefef trojan I was left feeling a little worried so I then installed Malwarebytes Anti-Malware just to be safe. The full scan came back clean but I’m still feeling a little paranoid that something is still lingering somewhere. Especially considering my PC has started occasionally hanging on the shut down screen until I manually turn it off at the power. Is there any way to do further checks to be 100% sure?

As it stands I have the free version of avast antivirus installed, Malwarebytes Anti-Malware and Windows fire wall switched on. Are there any other programs you would recommend me using to increase my protection and security?

Please attach your logs.
http://forum.avast.com/index.php?topic=53253.0

h

h

Any ideas based on these logs? Not installed OTL, avast didnt seem to like it when I downloaded it? Where is this program from?

it is normal…avast complain every time the progam is updated, if avast want to sandbox it select run normal

anyway, attach the OTL logs…not copy and paste

Just run the OTL scan, to be honest there’s a hell of a lot of information in the two logs to just be posting them on the internet. Can anyone give me some guidelines on what I should be looking for?

Having had a read through this stood out in the extras file:

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

Hi,

If you require help you will need to attach the logs.

the extra.txt is as the name say just extra tech info…OTL.txt is the important one
using the OTL.txt the malware remover will create a fix…no OTL log means no fix

here is an example on how it is done
http://forum.avast.com/index.php?topic=98716.0

Hi,

Just so that you know, there is no information shown in an OTL log or any of the logs from the tools that we use that I myself would be uncomfortable about putting up here in the forums. I understand how you can be concerned but there is no reason to be.

When you get them posted I will look them over and see how we can fix you up. :slight_smile:

Having gone through the OTL log, with the help of google, I don’t think there is anything serious to worry about to be honest. Having said that I’ve decided to do a reinstall anyway, just to be safe and appease my paranoia. Thanks for the help thus far, from what I’ve seen on the forum you guys do an amazing job.

On a side note, I will be backing up all my data on a second internal hard drive that I have yet to install. These files are stored on my desktop in a folder as opposed to in the usual ‘my documents’. Is there any chance these could have been infected/altered somehow? Virus and malware scans come up clean.

Well without seeing your OTL logs I couldn’t tell you 100% that files aren’t infected, but if you are comfortable with how your system is running I am too.

Thanks for letting us know.

Jeffce, any way I can send the log to you direct without posting on the forum? Would just like to make sure I am not backing up something nasty.

Also I’m interested in furthering my knowledge further and noticed your were a member of UNITE. Any chance you could send me some information regarding the requirements, particularly the course content?

Hi,

Jeffce, any way I can send the log to you direct without posting on the forum? Would just like to make sure I am not backing up something nasty.
I am sorry but no. I can not allow help via PM for various reasons. If you are too concerned about what might be shown in the logs that are produced I would suggest you take your system to a private shop for them to help you and you will be assured that your privacy is still in tact. I appreciate your understanding.
I'm interested in furthering my knowledge further and noticed your were a member of UNITE.
If you click on my signature it will take you to the UNITE page and you can look under the UNITE Schools link and that will show you the various UNITE schools available. You can browse to each of them and look over them to choose which, if any, you would like to apply to. :)