| Windows 7: Trend Micro still finding threat in PendingDeletes after SFC operation |
03 Aug 2012
|
#1 | | Windows 7 Professional x64 |
Trend Micro still finding threat in PendingDeletes after SFC operation I posted yesterday about sudden threats from PTCH_ZACCESS.SIX popping up on my machine. Using the info on the Trend website, I ran an SFC scan on the Services.exe file, which it found as corrupt and supposedly restored it to its proper state.
Since then Trend has flagged a few other things, including a file called simply "n" listed as the threat TROJ_SIREF64.SM, which showed up in several places. Most of those were quarantined and removed on reboot, except for one that I removed myself this morning from the Local AppData folder in my user profile.
Now this morning Trend has thrown up another notification of that PTCH_ZACCESS.SIX threat, but this time it's a file called "$$DeleteME.services.exe.01cd70f09b4bc3fd.0000" in the Windows\winsxs\Temp\PendingDeletes folder. As I understand it, the files in this folder are created after an SFC scan. Right now I have 6 files in that folder, other files from 2009, not that one. So I guess that file is gone. But I cannot manually delete those other files. The other odd thing is that if I look at the Temp folder, PendingDeletes is not shown, despite Explorer being set to show hidden files and folders. The only folder shown is PendingRenames which has thousands of files in it.
I don't understand why all these threats are popping up all of a sudden. It all started after visiting the Orbea Bikes website yesterday (very high end bicycle manufacturer). I got a notification about an Adobe Flash update, but the update was one version older than what was already installed on my machine. After that my Trend Micro started going crazy with all these threat notifications: Mal_Xin12, PTCH_ZACCESS.SIX, and TROJ_SIREF64.SM, contained within the files services.exe, that weird beacucqitear.exe file, this file called "n", and that $$DeleteMe.services.exe file.
Could there be something else malicious on my machine that's creating this stuff after Trend or myself finds the files and deletes them? | My System Specs |
| System Manufacturer/Model Number Dell Studio XPS 8100 OS Windows 7 Professional x64 CPU Core i7 870 2.93 GHz Motherboard OEM Memory 12 GB DDR3-1333 (2x 4GB + 2x 2GB) Graphics Card ATI Radeon HD 5770 1GB Sound Card on-board Monitor(s) Displays Dell Ultrasharp 24" + Dell 21" widescreen Screen Resolution 1920x1200 + 1920x1080 Keyboard Logitech Mouse Logitech PSU OEM Case OEM Cooling OEM Hard Drives 1 TB |
03 Aug 2012
|
#2 | | Windows 7 Home Premium 32 bit In a house with a cat trying to kill me |
If sounds as if you have one of the newer Sirefef variants. The newer variants are hard to remove, as they take advantage though the registry by presenting a genuine MS file & then switching over to the infected file, thus eluding complete detection.
MS is recommending a complete reinstall for Sirefef and doing a disk wipe would also be a good idea. Encyclopedia entry: Win32/Sirefef - Learn more about malware - Microsoft Malware Protection Center Quote: Caution: Win32/Sirefef is a dangerous threat that uses advanced stealth techniques in order to hinder its detection and removal. Particular variants of Win32/Sirefef may also make lasting changes to your computer that will NOT be restored - some system files may be irrevocably corrupted and essential security services may be disabled.
Due to the severe consequences associated with this threat, you may need to reinstall your Windows operating system and other computer programs, and restore your files and data from backup. Clean Install Windows 7 | My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
03 Aug 2012
|
#3 | | Windows 7 Professional x64 |
holy smokes man, that's crazy. Could I have gotten this thing just from going to a bicycle manufacturer's website?
*edit*
I just ran a complete, full scan with MBAM, full scan with Spybot S&D, and scan with TDSSKilller, all in safe mode in an administrator account. Nothing at all came up in any scan. I guess I'll wait and see if there are any more problems. | My System Specs | | System Manufacturer/Model Number Dell Studio XPS 8100 OS Windows 7 Professional x64 CPU Core i7 870 2.93 GHz Motherboard OEM Memory 12 GB DDR3-1333 (2x 4GB + 2x 2GB) Graphics Card ATI Radeon HD 5770 1GB Sound Card on-board Monitor(s) Displays Dell Ultrasharp 24" + Dell 21" widescreen Screen Resolution 1920x1200 + 1920x1080 Keyboard Logitech Mouse Logitech PSU OEM Case OEM Cooling OEM Hard Drives 1 TB |
05 Aug 2012
|
#4 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
If you know the physical location of the file, you can always submit it to Virus Total for 40+ opinions. https://www.virustotal.com/
A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
05 Aug 2012
|
#5 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
Patrick, Borg has given you excellent advice. | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
05 Aug 2012
|
#7 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
If so, here are some instructions to run a scan there from a security expert: - Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the ActiveX control to install
- Click Start
- Make sure that the option Remove found threats and the Scan Archives options are ticked.
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish
- Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera Trend Micro still finding threat in PendingDeletes after SFC operation problems? All times are GMT -5. The time now is 04:22 PM. | |