Windows 7 Services.exe Trojan problem

Hi there - the name’s Jeff.

For quite a while, now, ive been getting messages every few minutes from avast! telling me a series of Trojans have been blocked from C:/Windows/Installer. They state something in regards to Win32: Sirefef-AOO and Win32:Malware-gen. The problem is the system cannont detect the files. This is a constant problem. Any help would be most appreciated!

yepp…you seem to have the ZeroAcess rootkit

follow this guide and attach the logs…not copy and paste http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR

when done the removal experts will be notified and help you clean it

Monitoring. :slight_smile:

Do you still need help?

I believe i might. This morning avast! asked me to run a boot kit scan and so i did. Currently scanning, it has found hundreds of infected files located in the c:\windows\installer folder and is in the process of deleting them ALL. They are all files that carry a “trz” in the name. My worrybis that im deleting hundreds of Windows files. Is this ok? The scan states these files are either infected with Win32 Malware-gen or Win32 Access-pb. I tried to repair the files and the repair constantly failed. It would then ask me to delete. I eventually got tired of hitting the delete button all the time so i hit “delete all”.

follow the guide i gave you above and attach the logs so that Jeffce have something to work with

Should i end the scan prematurely?

yes, you seem to have ZeroAccess rootkit and avast cant remove that…
jeffce will do that with help from the requested logs

Hi,

In addition to the scans you have already been asked to run please do the following…

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

[*]Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
[*] Double click dds to run the tool.
[*]When done, two DDS.txt’s will open.
[*]Save both reports to your desktop.

Please attach the contents of the following in your next reply:

DDS.txt

Attach.txt

Do you still need help?