Sirefef Trojan - Site redirects and more damage to my laptop

Never mind. Had to reboot 4 or 5 times before the system came back normal. Ran TDSKiller . No threats found. Running Combofix now.

Combofix indicated that the laptop is infected with the zeroaccess malware. The popup said the laptop will be rebooted by Combofix and that I shouldnt do a manual reboot. But the laptop isn’t rebooting. Only explorer was closed.

Did a manual reboot.

Could you post the combofix log please

Both LAN and Wireless are disabled now. Can’t connect to Internet. How do I get back to Internet? Also, there is an application called Mini Broswer running behind whenever I lock the desktop.

I am attaching the files from another computer.

Ran FSS (farbar service scanner) scan with “Internet services” and “Windows Firewall” options.
Attached is the log file.

sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is OK. The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK.

Download sharedacces.reg from here http://windowsxp.mvps.org/reg/sharedaccess.reg to your desktop
Double click the file and allow it to merge
Reboot

Then Go Start > Run and type/copy/paste the following command :

CMD /K NETSH FIREWALL RESET

Enter the command

Reboot

Then re-run Farbar and let me know if the net is working

Added the reg file info. Also ran the windows command followed by FSS. Internet still not working.

Also, when I try to open Windows Firewall it says “Windows cannot start the Windows Firewall/Internet connection Sharing (ICS) service”.

OK lets re-run Farbar and see what is missing

run farbar service scanner

http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FSS-1.jpg

Tick “All” options.
Press “Scan”.
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Here it is.

OK there are some services not running that should be

Download Windows Repair (all in one) from this site

Install the programme then run

Go to step 2 and allow it to run Disc check

http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture3.gif

Once that is done then go to step 3 and allow it to run SFC

http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture.gif

On the start repairs tab select advanced mode and click start

http://i1224.photobucket.com/albums/ee362/Essexboy3/Capture1.gif

Leave the default options selected and start the repairs

Thanks essexboy :slight_smile: Internet is working now. System is definitely slower than before. Will monitor the system health today and report it.

I see an application called ‘Mini Web Browser’ everytime I lock and unlock the windows. It started appearing only when I was trouble shooting with your help in the past couple of days.

OK now we have a semblance of normality lets see if we can resolve the remaining issues

Please download a fresh copy of OTL as it has been updated

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in
[b]netsvcs
%SYSTEMDRIVE%*.exe
/md5start
consrv.dll
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
C:\Windows\assembly\tmp\U*.* /s
%Temp%\smtmp\1*.*
%Temp%\smtmp\2*.*
%Temp%\smtmp\3*.*
%Temp%\smtmp\4*.*

C:\commands.txt echo list vol /raw /hide /c
/wait
C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
/wait
type c:\diskreport.txt /c
/wait
erase c:\commands.txt /hide /c
/wait
erase c:\diskreport.txt /hide /c
CREATERESTOREPOINT[/b]
[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs

I ran OTL and the OTL.Txt log is attached. However, I did not get any extras log this time.

OK it now looks malware free - so what problems remain to solve ;D

Glad to hear that :slight_smile: I will continue to monitor and report issues if any. Should I uninstall any apps that were installed in the past 3 days?

Thanks again for all your help. Really appreciate it.

As soon as you are happy I will remove them and tidy up, just in case we need to use one of them ;D