Trying to cure a Sirefef-PL infected machine

I get that avast error every time I restart.

only slowly, and I’ll fix

step1

Re-run OTL.exe.

[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.



:Files
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
netsh int ip reset c:\resetlog.txt  /c

:commands
[emptytemp]


[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.

I need the c: \ resultlog.txt

**

step2

Delete ComboFix icon, and download new ComboFix to the desktop
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Re-run combofix
Attach the contents of the log in your next reply

step3

Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.

[*] Make sure that all options are checked.
[*] Press “Scan”.
[] It will create a log (FSS.txt) in the same directory the tool is run.
[
] Please attach FSS.txt log to your reply.

I ran another scan and did the run fix portion. Here are both logs in that order. Working on combo atm.

ComboFix and FSS log.

Download MCShield from one of the following links:

MyCity - Official download link
Softpedija - Mirror download link

[*] Double click MCShield-Setup to install the application.
[*] Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
[*] Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.

When all scanning is done, you need to attach a logreport that has made MCShield.

Start → All Programs → MCShield → Logs

Attach here → AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.


Open notepad and copy/paste the text present inside the code box below:



File::
c:\program files (x86)\GUM2FDA.tmp
c:\program files (x86)\GUM8B03.tmp
c:\program files (x86)\GUM6F46.tmp
c:\windows\Tasks\Norton Security Scan for Kristian.job

Folder::
c:\progra~2\NORTON~2
c:\program files (x86)\GUM2FDA.tmp
c:\program files (x86)\GUM8B03.tmp
c:\program files (x86)\GUM6F46.tmp

KillAll::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

Firefox::
FF - ProfilePath - c:\users\Kristian\AppData\Roaming\Mozilla\Firefox\Profiles\l2oidhu1.default\
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=394&systemid=406&sr=0&q=

RegLockDel::
[HKEY_LOCAL_MACHINE\software\McAfee]


Save this as CFScript.txt

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )


You need to download following files to your Desktop.

https://www.dropbox.com/s/api9frrvly0fn4u/BITS.reg
https://www.dropbox.com/s/6ia9gtmsaf7kj2k/MpsSvc.reg
https://www.dropbox.com/s/2e24qtxhjuxaijr/SharedAccess.reg
https://www.dropbox.com/s/6ntbcz5av2k51mv/WinDefend.reg
https://www.dropbox.com/s/dozt6f6sjzlxu7i/wuauserv.reg

Run thouse files double clicking one by one.
Running on each file you’ll get a pop-up warning about the registry edit.
Just click on YES/OK.

Restart your computer.

Re-run FSS and attach here fresh FSS.txt log

The SharedAccess.reg was access denied.

Download Windows Repair (all in one) from this site

Install the programme then run

https://dl.dropbox.com/u/73555776/waio%20start.JPG

Go to step 3 and allow it to run SFC

https://dl.dropbox.com/u/73555776/waio%20step3.JPG

On the start repairs tab click start

https://dl.dropbox.com/u/73555776/waiostart%20rep.JPG

Select the following items and tick restart system when finished

https://dl.dropbox.com/u/73555776/waio%20rep%20list.JPG

Did the following. Still getting avast error and exclamation points for wireless and ethernet.

http://www.avast.com/uninstall-utility

Temporarily uninstall Avast, reboot PC. Re-run FSS and attach here fresh FSS.txt log

FSS.

You need to download following file to your Desktop.

http://www.speedyshare.com/YBE6G/fix.reg

double clicking

Just click on YES/OK. Reboot.

Re-run FSS
Re-run Complete repair of the Internet + MiniToolBox

Attach the contents of the logs in your next reply.

Getting “Could not find wuauclt.exe” on CIntRep.

Should I try uninstalling ethernet and wireless drivers and reinstall?

Try it.

Changed levels of some services, no rules, random problems (ZA Tootkit). I am trying find a solution.

Reinstalling no worky.

You had a Zero Access infection. The consequence of this is the problem with the internet.
rootkit has changed the value of some services, random, very hard to find.
I’m trying to find a solution, please for your patience.

Thank you Argus. I have yet to thank you for all your help. I studied network security, but all this has made me realize malware is far more treacherous to a machine then I expected. Its far beyond running MBAM to remove it or going through a how to about “How to Remove Windows Internet Security 2012”. Without your help i would of just reformatted and went on. If there is anything you can reference me to on how you go by resolving these types of issues it would be great.

step1

Follow this manual and reboot computer
http://support.microsoft.com/kb/971058

Reset router.

  • Copy and Paste everything from the Code box into Notepad:
@echo off

sc config wuauserv start= auto

net stop wuauserv

net start wuauserv
  • Go to File > Save As
  • Save File name as Fix.bat
  • Close Notepad, and double-click Fix.bat

If you still do not have Internet access, do the following:

Go to Start>Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
On the General tab, click Install and a popup window will open.
Select Protocol from the list and then click Add.
A new window opens, click Have Disk…
In the browse… box type c:\windows\inf.
Click OK.
Select Internet Protocol (TCP/IP), and then click OK.
Restart and check the connection.

I need a new FSS and MiniBox logs.

I am on a Windows 7 machine if I didnt mention that. Just saying cause I saw your path to network connections. Internet did not work after batch file. Doing the TCP\IP portion at the moment. Will send logs shortly.

Doing fix manually, and regsvr32.exe “The module mshtml.dll was loaded but the entry-point DllRegisterServer was not found”. Same for shdocvw.dll, browseui.dll, wuaueng.dll, qmgr.dll
“The module “msxml.dll” failed to load”. Same with gpkcsp.dll, sccbase.dll, slbcsp.dll, initpki.dll, wuaueng1.dll, wucltui.dll, wuweb.dll, muweb.dll

“Reset Winsock. To do this, type the following command at a command prompt, and then press ENTER:
netsh reset winsock.” Following command was not found: reset winsock (I tried netsh winsock reset, but it gave me The system cannot find the file specified.

After running MiniBox the exclamation point dissapeared. Then I rebooted and it showed back up.

Sorry, the only thing you can try to repair the Windows.

http://www.sevenforums.com/tutorials/3413-repair-install.html