also Win32:Sirefef-PL [RTK]
and Win 32Downloader-PKU
I have downloaded all the fixes on here and used them and I am still having problems what can I do?
also Win32:Sirefef-PL [RTK]
and Win 32Downloader-PKU
I have downloaded all the fixes on here and used them and I am still having problems what can I do?
I have responded in the other post you made, you have to do the analysis phase first before a malware specialist can analyse it and construct a fix that is specifically for the users system - they are unique and shouldn’t be used on other systems.
Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.07.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
jhenderson65 :: HOME [administrator]
Protection: Enabled
8/7/2012 9:49:15 AM
mbam-log-2012-08-07 (09-49-15).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 194452
Time elapsed: 7 minute(s), 31 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 25
HKCR\CLSID{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\TypeLib{1D4DB7D0-6EC9-47a3-BD87-1E41684E07BB} (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\Interface{1D4DB7D1-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\FunWebProductsInstaller.Start.1 (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\FunWebProductsInstaller.Start (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\CLSID{D9291F9E-7010-4D7A-8DF6-455DEEF8EF51} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCR\TypeLib{8006F89E-63A1-402A-8DB7-08A4C58F95AA} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCR\Interface{D4256C66-8177-4E19-8A13-2D43B2282D0D} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCR\lptlIE.TextLinks.1 (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCR\lptlIE.TextLinks (PUP.LivingPlay) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{D9291F9E-7010-4D7A-8DF6-455DEEF8EF51} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings{D9291F9E-7010-4D7A-8DF6-455DEEF8EF51} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{D9291F9E-7010-4D7A-8DF6-455DEEF8EF51} (PUP.LivingPlay) → Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{66D8FBA6-D90F-40A9-AC55-84896F79CA69} (Trojan.BHO) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{66D8FBA6-D90F-40A9-AC55-84896F79CA69} (Trojan.BHO) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) → Quarantined and deleted successfully.
HKCR\bho_project.bho_object (Trojan.BHO) → Quarantined and deleted successfully.
HKCR\bho_project.bho_object.1 (Trojan.BHO) → Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start.1 (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKLM\SOFTWARE\FunWebProducts (PUP.MyWebSearch) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) → Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 7
C:\Program Files (x86)\Object (PUP.FCTPlugin) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts (PUP.MyWebSearch) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts\Installr (PUP.MyWebSearch) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts\Installr\2.bin (PUP.MyWebSearch) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts\Installr\2.bin\chrome (PUP.MyWebSearch) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts\Installr\3.bin (PUP.MyWebSearch) → Quarantined and deleted successfully.
C:\Program Files (x86)\FunWebProducts\Installr\3.bin\chrome (PUP.MyWebSearch) → Quarantined and deleted successfully.
Files Detected: 7
C:\Users\jhenderson65\AppData\Local\Temp\DM\Installer_for_windows-movie-maker_041202\ExecIwantThis.exe (Adware.GamePlayLabs) → Quarantined and deleted successfully.
C:\Users\jhenderson65\AppData\Local\Temp\DM\Installer_for_windows-movie-maker_041202\IWantThis_PPI.exe (Adware.GamePlayLabs) → Quarantined and deleted successfully.
C:\Windows\Installer{640e0a8c-968a-63b3-a68f-73095a00ca86}\U\00000008.@ (Trojan.Dropper.BCMiner) → Quarantined and deleted successfully.
C:\Windows\Installer{640e0a8c-968a-63b3-a68f-73095a00ca86}\U\000000cb.@ (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Program Files (x86)\Object\status.txt (PUP.FCTPlugin) → Quarantined and deleted successfully.
C:\Program Files (x86)\Object\config.ini (PUP.FCTPlugin) → Quarantined and deleted successfully.
C:\Program Files (x86)\Object\status2.txt (PUP.FCTPlugin) → Quarantined and deleted successfully.
(end)
now what
That is only the first one, you need to run OTL and aswMBR; then attach the otl.txt, extras.txt logs and the aswMBR.txt. When you have all of those a malware removal specialist can analyse them and formulate a fix.
Since you have been posting about this same thing in three places, the other posts have been removed for clarity and to avoid duplication of effort for those trying to help:
These are the full instructions and applications that need to be run:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.
scans ran
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Files C:\Windows\assembly\GAC_32\Desktop.ini C:\Windows\assembly\GAC_64\Desktop.ini C:\Windows\Installer\{640e0a8c-968a-63b3-a68f-73095a00ca86} C:\Users\jhenderson65\AppData\Local\{640e0a8c-968a-63b3-a68f-73095a00ca86}:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
THEN
Download and Install Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png
http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png
[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.
Notes:
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
FINALLY
https://dl.dropbox.com/u/73555776/FSS.GIF
Tick “All” options.
Press “Scan”.
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.