Solved Many backdoors/various Trojans/rootkit. Shutdowner present

MelancholyRose

New member
Member
VIP
Local time
10:42 AM
Messages
156
To start off, I got this virus a few weeks ago. My graphics card's fan failed and I fixed it by now.

This virus entered my system by what I assume was an e-mail link. I was receiving various random junk mails that I tried to unsubscribe from. A few minutes later weird sounds and advertisements began happening. Next thing I knew, Microsoft Security Essentials was uninstalled and my firewall was down/missing. I reinstalled Essentials to find out what I was infected with. It repeatedly said Sirefef.

A shutdowner of some kind got installed and wouldn't allow me to work on my HDD for more than 30 seconds. It will pop up with an error message as soon as I get into Windows, EVEN in Safe Mode. I didn't have enough time to get a new malware-remover of some kind to restore the system, because my computer is only operational for 30 seconds on startup.

I made a Kaspersky Rescue Disk, and started it up. I scanned everything and it found many Trojans. I deleted/disinfected them. I got back into Windows in Safe Mode and I still get a "critical error" message and it shuts down in 30 seconds again. So I ran the Rescue Disk a second time. It didn't find any "threats" exactly, except for:

-Trojan program: Exploit.Jav - a .class file found in the cache
-Trojan program: Trojan.Win - found in AppData/Local/Temp and is a jumble of numbers. It's an executable file.

I would remove these via the Rescue Disk, but it won't let me do anything with them. It says "Status: Absent" under their detection and says "Not Found." It only appears under the "All" dropdown menu, not "Active Threats." Kind of sneaky, if this is the Trojan's work, because I can't delete them.

I downloaded a bunch of other anti-virus programs, including the rootkit removal tool from Kaspersky (TDSSKiller), EZSireFix, HitmanPro, ServicesRepair, and I have MalwareBytes already on the system, intending to use them, but I cannot get into Windows. I get a restart almost immediately, and yes, still in Safe Mode as well.

Is it possible to use the programs from a flash drive while in the Kaspersky Rescue Disk?
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i5-4570 CPU @ 3.20GHz8GB DDR3-1596 - Dual ChannelNVIDIA GeForce GTX 750 Ti SC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
All right. I'll try that. Hopefully it's reliable. I've kind of hit a speed bump trying to kill this sucker.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Yes it is reliable. Everyone here recommends that if MSE or Malwarebytes doesn't get em. And i bet.

-Justin
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i5-4570 CPU @ 3.20GHz8GB DDR3-1596 - Dual ChannelNVIDIA GeForce GTX 750 Ti SC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
I'm actually honestly very shocked that the Kaspersky Disk couldn't beat it all. Kaspersky is usually a great anti-virus software company :/ Oh well, I'll try this, too. If it could at least get the shutdowner off of there I can use other programs to fix the residual damage.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
I do hope WDO will work for you. I also heard that Kaspersky is a good A/V. But not even the best A/V can take care of every virus.

-Justin
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i5-4570 CPU @ 3.20GHz8GB DDR3-1596 - Dual ChannelNVIDIA GeForce GTX 750 Ti SC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
Windows Defender Offline cannot be started.

Error: Unable to detect a Windows system drive. This could be due to missing drivers, an encrypted drive, or a corrupted Windows installation.

Error Code: 0x8004cc01

That... doesn't look good at all.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
It repeatedly said Sirefef.

Depending on the variant you have, it may have done irreparable damage.

Encyclopedia entry: Trojan:Win32/Sirefef.AC - Learn more about malware - Microsoft Malware Protection Center

Win32/Sirefef is a multi-component family of malware that uses stealth to hide its presence on an affected computer. Due to the nature of this threat, the payload may vary greatly from one infection to another, although common behavior includes:

  • Downloading and executing of arbitrary files
  • Contacting remote hosts
  • Disabling of security features

Caution: Win32/Sirefef is a dangerous threat that uses advanced stealth techniques in order to hinder its detection and removal. Particular variants of Win32/Sirefef may also make lasting changes to your computer that will NOT be restored - some system files may be irrevocably corrupted and essential security services may be disabled.

As a consequence of being infected with this threat, you may need to reinstall your Windows operating system and other computer programs, and restore your files and data from backup.
A clean reinstall would be the best/safest option.

http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i5-4570 CPU @ 3.20GHz8GB DDR3-1596 - Dual ChannelNVIDIA GeForce GTX 750 Ti SC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
Erm... well, should I try repairing first before reinstalling?

What recovery option should I be using, by the way? Startup repair, system restore, etc?
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Try a system restore to the point before you clicked on the spam and such.

Like what borg said, it may not be fixable.

-Justin
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i5-4570 CPU @ 3.20GHz8GB DDR3-1596 - Dual ChannelNVIDIA GeForce GTX 750 Ti SC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
Click on Repair your computer. (See screenshot below)

5. Select which operating system you want to restore and the click on Next. (See screenshot below)
NOTE: If Windows 7 is not listed here, or it is blank, then it is ok. Click on Next anyway.
It wasn't listed, it was blank, and I clicked Next anyway. I went to System Restore and it said:

To use System Restore, you must specify which Windows installation to restore. Restart this computer, select an operating system, and then select System Restore.

I thought I could leave it blank?

I didn't click Load Drivers. Should I try that?
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Although you might be able to get a deeply infected machine back into a 'workable' state it will likely take more than one program to do it.

But even if you can get it back into that 'workable' state I wouldn't trust it. I'd wipe that disk clean and reinstall. Quicker that way, and you can then be confident that it's secure.

Back up all your data to reliable media first though.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
OS
Windows 7 Ultimate x64
To use System Restore, you must specify which Windows installation to restore. Restart this computer, select an operating system, and then select System Restore.

I thought I could leave it blank?

I didn't click Load Drivers. Should I try that?

System Restore might work, but you should be aware that your restore points can contain the malware too. Definitely contains it if you've been infected for some time.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
OS
Windows 7 Ultimate x64
I need to get that shutdown to stop happening before I can back anything up. I'm having a friend help me.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
The easiest thing to do is to remove the drive and slave it into another computer (with up to date virus definitions, of course). Copy your essential files to the other computer. Put the drive back into the original computer, and reinstall Windows.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Core i7-2670QM8GB DDR3 PC3-10600Intel HD Graphics 3000 + GeForce GT 540M
Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
Apparently the Services.exe file is damaged, and that's what's causing the shut downs, not a virus. I thought to do an sfc scannow, but for some reason my computer just doesn't show my OS. It acts like I don't have one, even though I definitely do.

What I think is causing that is, I use a RAID 1 mirror. My other hard drive isn't being used right now, it hasn't been used for a while, so I'm using only the one drive. Do I need my RAID driver to get to my OS?

If so, do I need to use RAID drivers or Chipset drivers? http://support.amd.com/us/gpudownload/windows/Pages/raid_windows.aspx [EDIT: I'm thinking it's the AHCI Controller Driver under chipsets.]

EDIT: Looks like this is probably it. http://www.sevenforums.com/tutorials/68942-sata-drivers-load-windows-recovery-options.html
 
Last edited:

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
My mother in law's laptop got infected and I got tired of fighting this rootkit because of the afterall damage to core files which SFC couldnt fix, ended wiping the disk and reinstalling clean, one thing I'm clueless about is how is this infection spreaded?
 

My Computer My Computer

At a glance

Microsoft Windows 10 Professional / Windows 7...Intel i5-357016GB DDR3AMD Radeon HD 7850 2GB
Computer type
PC/Desktop
OS
Microsoft Windows 10 Professional / Windows 7 Professional
CPU
Intel i5-3570
Motherboard
Lenovo Mahobay
Memory
16GB DDR3
Graphics Card(s)
AMD Radeon HD 7850 2GB
Sound Card
(1) Realtek HD Audio (2) AMD HD Audio
Monitor(s) Displays
LG LS192WS
Screen Resolution
1440 x 900 @ 32bit color
Hard Drives
(1) SUV300S37A/120G (2) ST3500413AS SATA Disk Device AHCI mode enabled.
PSU
Corsair HX620
Case
Thermaltake V4 Black Edition
Cooling
Cooler Master Hyper 212 + Artic Silver 5 on CPU/GPU
Keyboard
Dell SK-8115
Mouse
Razer Copperhead with MAPED mat (awesome!)
Internet Speed
100 Mbps up/down
Browser
Chrome
Judging on what I've read/been told about Sirefef is that if you try to remove it, it hides in system files and copies itself to Registry keys and such.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
This sounds like the Zero Access Rootkit. It has created a hidden partition to hide itself from being found and fixed. This is quite a nasty Rootkit! :mad:

Save what you can (pictures, important documents), then wipe your OS and do a "clean" install.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top