Help with OTL and virus

Hoping for some help with an infection I seem to have picked up. Ran Avast with boot scan, that fixed some problems. Have a Sirefef and other issues, I’m guessing a rootkit problem? I’m also getting an error with MsMpRes.dll saying Error: Incorrect Function (after Avast scan). I suspect my main issue is with the ZeroAccess registry entries…My OTL log is attached (too long to insert):

Thanks in advance!

hi abaek5,

Thanks for the OTL log. You were correct to attach the log, 'tis how we do things. :wink:

Please see this link: http://forum.avast.com/index.php?topic=53253.0

Please download and run the following programs:

  • AdwCleaner
  • Malwarebytes
  • aswMBR.exe
    Ok to quarantine and remove anything AdwCleaner and Malwarebytes find. Do not run a fix with aswMBR.exe however, log is needed only. Attach all three new logs in your next reply. A certified malware expert will be notified when logs are attached.

Thanks for your help! I’ve attached the following logs:

  • ADW
  • aswMBR
  • Malwarebytes from yesterday (found a few items, now quarantined)
  • Malwarebytes from today (showed clean)
  • jpg of the items in the quarantine list (is there any reason I would leave them quarantined as opposed to deleting?)

Thanks again!

jpg of quarantined items here, couldn’t attach to last post

Hi you did not run the full OTL scan so that I could check for reparse points, anyhow I will run a separate programme for that

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach the log back here.
[*]The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

FRST and Addition logs are attached. Thanks again

Download the attached fixlist.txt to the same location as FRST
Run FRST as before and press fix
A log will be generated, please post that and an update on how the computer is behaving