
04-13-2012 02:32 PM
A couple days ago I got this virus and haven't been able to remove it. TM keeps poping up every couple minutes saying it has removed a file always with a different name and from what I can tell they have all been .dll files. Occasionally it'll have to restart to remove the file. I have ran Malwarebytes and it detected a bunch stuff and "fixed" those too. Can someone help get rid of this?
Attached is a HJT log, my last scan log, and a MB log.
Thanks!
04-13-2012 10:44 PM
Welcome aboard! ![]()
This is a new varient of sirefef infection which is tad nasty...
Download OTL to your Desktop.
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
explorer.exe
netbt.sys
atapi.sys
volsnap.sys
redbook.sys
lsi_sas.sys
lsi_scsi.sys
cdrom*
tcpip.sys
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
C:\Windows\assembly\tmp\U\*.* /s
C:\Program Files\Common Files\ComObjects\*.* /s
CREATERESTOREPOINT
NEXT
Download aswmbr.exe ( 1.8mb ) to your desktop.
http://public.avast.com/~gmerek/aswMBR.htm
Double click the aswMBR.exe to run it Click the "Scan" button to start scan.

Click the [Scan] button to start scan

On completion of the scan click [Save log], save it to your desktop and post in your next reply.
04-14-2012 01:12 PM
Thanks for your help. Attached are the logs you asked for.
04-14-2012 01:48 PM
I don't think I checked the scan all users box when I did the OTL scan. Here is a new log.
04-14-2012 09:06 PM
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
If u have malwarebytes 1.5 or later disable it for the duration of this run
Run OTL
:OTL DRV - File not found [Kernel | On_Demand | Unknown] -- -- (alav5qyz) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ai912fr1) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) ipconfig /flushdns /c :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [CLEARALLRESTOREPOINTS] [Reboot]
NEXT
Download ComboFix from the any of the locations given in this website:


04-15-2012 03:14 AM
Ok, whenever I go to do the OTL scan with the custom fixes from your last reply the icons and start bar go away and then my pc locks up and doesn't do anything. I let it sit for a few hours and nothing changes. I've tried it twice but have had to manually power down the pc. Any thoughts on what could be wrong?
04-15-2012 03:23 AM - edited 04-15-2012 03:29 AM
the start menu and desktop disappearing is normal...just move directly to combofix step for now.Skip OTL for now and do the below before moving on to combofix step:
Please download ATF Cleaner by Atribune.
04-15-2012 07:28 AM
Ok, I click on the link you sent me and Trend Micro pops up in my browser saying it's a dangerous page.
"Trend Micro has confirmed that this website can transmit malicious software or has been involved in an online scan or fraud."
Even if I try to go to the www.atribune.org main page it says that. Should I ignore it and go on?
04-15-2012 07:29 AM
Ignore it its safe as hell!
04-15-2012 02:12 PM
Ok here is my combofix log. I did have problems with combo fix too. It removed my desktop like you said it would, but then it just sat there. For a long time...like a couple of hours. I know it said not to manually restart but I did anyway. It did seem to finish the job once it restarted, but I'm not sure if I messed anything up by doing that. I did delete the temp files before hand with the program you gave me and I did make sure to shut down TM and MB before hand.
Thanks a lot for your help with all this!
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
