Trend Micro still finding threat in PendingDeletes after SFC operation

PatrickGSR94

New member
Member
VIP
Local time
2:54 AM
Messages
182
I posted yesterday about sudden threats from PTCH_ZACCESS.SIX popping up on my machine. Using the info on the Trend website, I ran an SFC scan on the Services.exe file, which it found as corrupt and supposedly restored it to its proper state.

Since then Trend has flagged a few other things, including a file called simply "n" listed as the threat TROJ_SIREF64.SM, which showed up in several places. Most of those were quarantined and removed on reboot, except for one that I removed myself this morning from the Local AppData folder in my user profile.

Now this morning Trend has thrown up another notification of that PTCH_ZACCESS.SIX threat, but this time it's a file called "$$DeleteME.services.exe.01cd70f09b4bc3fd.0000" in the Windows\winsxs\Temp\PendingDeletes folder. As I understand it, the files in this folder are created after an SFC scan. Right now I have 6 files in that folder, other files from 2009, not that one. So I guess that file is gone. But I cannot manually delete those other files. The other odd thing is that if I look at the Temp folder, PendingDeletes is not shown, despite Explorer being set to show hidden files and folders. The only folder shown is PendingRenames which has thousands of files in it.

I don't understand why all these threats are popping up all of a sudden. It all started after visiting the Orbea Bikes website yesterday (very high end bicycle manufacturer). I got a notification about an Adobe Flash update, but the update was one version older than what was already installed on my machine. After that my Trend Micro started going crazy with all these threat notifications: Mal_Xin12, PTCH_ZACCESS.SIX, and TROJ_SIREF64.SM, contained within the files services.exe, that weird beacucqitear.exe file, this file called "n", and that $$DeleteMe.services.exe file.

Could there be something else malicious on my machine that's creating this stuff after Trend or myself finds the files and deletes them?
 

My Computer My Computer

At a glance

Windows 7 Professional x64Core i7-4790K Devil's Canyon Quad Core 4.0 GHzG.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x ...EVGA (nVIDIA) GTX 960 4 GB GDDR5
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built PC workstation
OS
Windows 7 Professional x64
CPU
Core i7-4790K Devil's Canyon Quad Core 4.0 GHz
Motherboard
ASUS Z97-E/USB3.1 ATX
Memory
G.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x 8GB)
Graphics Card(s)
EVGA (nVIDIA) GTX 960 4 GB GDDR5
Sound Card
on-board
Monitor(s) Displays
2x Dell Ultrasharp 24" U2415
Screen Resolution
2x 1920x1200
Hard Drives
Crucial MX200 500GB 2.5" SSD SATA III 6 GB/sec
PSU
Rosewill Glacier 700M 700-watt
Case
Fractal Design Define R4 Silent PC mid-tower
Cooling
OEM PSU cooler, 3x 140mm case fans (2 intake, 1 exhaust)
Keyboard
Logitech
Mouse
Logitech
Internet Speed
100+ Mbps
Antivirus
BitDefender
Browser
Firefox/Chrome
If sounds as if you have one of the newer Sirefef variants. The newer variants are hard to remove, as they take advantage though the registry by presenting a genuine MS file & then switching over to the infected file, thus eluding complete detection.

MS is recommending a complete reinstall for Sirefef and doing a disk wipe would also be a good idea.

Encyclopedia entry: Win32/Sirefef - Learn more about malware - Microsoft Malware Protection Center

Caution: Win32/Sirefef is a dangerous threat that uses advanced stealth techniques in order to hinder its detection and removal. Particular variants of Win32/Sirefef may also make lasting changes to your computer that will NOT be restored - some system files may be irrevocably corrupted and essential security services may be disabled.

Due to the severe consequences associated with this threat, you may need to reinstall your Windows operating system and other computer programs, and restore your files and data from backup.
http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
holy smokes man, that's crazy. Could I have gotten this thing just from going to a bicycle manufacturer's website?

*edit*
I just ran a complete, full scan with MBAM, full scan with Spybot S&D, and scan with TDSSKilller, all in safe mode in an administrator account. Nothing at all came up in any scan. I guess I'll wait and see if there are any more problems.
 

My Computer My Computer

At a glance

Windows 7 Professional x64Core i7-4790K Devil's Canyon Quad Core 4.0 GHzG.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x ...EVGA (nVIDIA) GTX 960 4 GB GDDR5
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built PC workstation
OS
Windows 7 Professional x64
CPU
Core i7-4790K Devil's Canyon Quad Core 4.0 GHz
Motherboard
ASUS Z97-E/USB3.1 ATX
Memory
G.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x 8GB)
Graphics Card(s)
EVGA (nVIDIA) GTX 960 4 GB GDDR5
Sound Card
on-board
Monitor(s) Displays
2x Dell Ultrasharp 24" U2415
Screen Resolution
2x 1920x1200
Hard Drives
Crucial MX200 500GB 2.5" SSD SATA III 6 GB/sec
PSU
Rosewill Glacier 700M 700-watt
Case
Fractal Design Define R4 Silent PC mid-tower
Cooling
OEM PSU cooler, 3x 140mm case fans (2 intake, 1 exhaust)
Keyboard
Logitech
Mouse
Logitech
Internet Speed
100+ Mbps
Antivirus
BitDefender
Browser
Firefox/Chrome
If you know the physical location of the file, you can always submit it to Virus Total for 40+ opinions.

https://www.virustotal.com/

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Patrick,

Borg has given you excellent advice.
 

My Computer My Computer

At a glance

MS Windows 7 Ultimate SP1 64-bitAMD A10-4600M6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)AMD Radeon HD 7660G
Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Eset online scanner will help you remove this particular infection

ESET Online Virus Scanner | ESET

If so, here are some instructions to run a scan there from a security expert:

  • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the option Remove found threats and the Scan Archives options are ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Back
Top