SFC Warning

Is the faulty symlink always MpEvMsg.dll, or is this just an example?

In case it's always MpEvMsg.dll:
  1. delete the symlink
  2. reinstall microsoft security essentials
Of course this doesn't remove ZeroAccess, but fixes the SFC problem(?) Or is this not the whole story

It's always on MpEvMsg.dll but there are many other files. I can't go into any details on the security side of things I'm afraid as I haven't finished my training yet, I just wanted to give you guys a heads up if you see SFC failing with this error :)
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
ESET Removal Tool

Hey guys, I hardly ever post but I thought this may help others with this particular problem. The ESET Sirefef removal tool does find and fix these symbolic links. You may have to run it with the /r switch to get it to repair the files if the main zaccess infection has already been removed.
 

My Computer My Computer

At a glance

Windows Vista 32 bitIntel Core 2 Duo E6550 2.33GHz4GBAMD Radeon HD 6670
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Optiplex 755
OS
Windows Vista 32 bit
CPU
Intel Core 2 Duo E6550 2.33GHz
Memory
4GB
Graphics Card(s)
AMD Radeon HD 6670
Antivirus
Bitdefender Free AntiVirus
Browser
Firefox
@Kaktussoft

Never thought of ZeroAccess as a story, but, your comment made me laugh. It is a story, and a long one!!


From what I have read...

The new ZeroAccess Rootkit variant can get in the system, make a mess of some services, and then go after the Microsoft Security Client and Windows Defender to set symbolic links.

If I understand correctly, looking into these gives a clue:
C:\Program Files\Microsoft Security Client\MpEvMsg.dll
C:\Program Files\Windows Defender\MpSvc.dll

Unfortunately, the above is "not the whole story"...

...the story continues, and using WD as an example, need to find and remove the symbolic links on the files of Windows Defender. Then, turn the page of the storybook, for the previous is not enough. The files altered permissions need reset!



There are now some tools that will take care of the problem, either entirely, or to some extent.

We can be sure tool developers are working incessantly to give this new ZeroAccess story, like many times before, a good ending.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Hey guys, I hardly ever post but I thought this may help others with this particular problem. The ESET Sirefef removal tool does find and fix these symbolic links. You may have to run it with the /r switch to get it to repair the files if the main zaccess infection has already been removed.

Hi tiberriver256,

Thank you so much for taking the time to sign up here to let me know about this tool! I really appreciate you efforts :) I have passed this information on, including the logs of it purging ZeroAccess from my VM, to the security community and this should really aid us in the fight.

Thanks again,

Tom
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Hey guys, I hardly ever post but I thought this may help others with this particular problem. The ESET Sirefef removal tool does find and fix these symbolic links. You may have to run it with the /r switch to get it to repair the files if the main zaccess infection has already been removed.

Hi tiberriver256,

Thank you so much for taking the time to sign up here to let me know about this tool! I really appreciate you efforts :) I have passed this information on, including the logs of it purging ZeroAccess from my VM, to the security community and this should really aid us in the fight.

Thanks again,

Tom
how does this work? Is the Sirefef removal tool a command line tool?
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Britton30,

Is the Sirefef removal tool a command line tool?

The answer is No and Yes!! :D Not trying to confuse you!!

The ESETSirefefCleaner tool is run like any other tool, double-click, and follow a certain routine, etc.

However, once done, if the system still has problems, you go to an elevated command prompt, and run the tool in manual repair mode: /r

Have not used this tool, and do not know whether it addresses MSE, or whether it resets the permissions of all the files affected in WD and MSE.

Tom might give it a whirl in his VM...
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Thanks, I'm totally unfamiliar with running stuff from command line. :confused:
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
If you keep it kind of basic, it's not difficult, once you get the hang of it. Bet you could do it if you wanted to.

If it goes beyond some basics, it is not for me either. :D

Messing with rootkits is kind of a post and pray deal. There are no guarantees.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
If you keep it kind of basic, it's not difficult, once you get the hang of it. Bet you could do it if you wanted to.

If it goes beyond some basics, it is not for me either. :D

Messing with rootkits is kind of a post and pray deal. There are no guarantees.

I thought ZeroAccess wasn't a rootkit any more? I suppose it depends how you define a rootkit, but I don't think user mode 'rootkits' are real rootkits :D It switched to usermode in the last variant and I'm pretty sure this is the same because I can't see a driver anywhere.


Major shift in strategy for ZeroAccess rootkit malware, as it shifts to user-mode | Naked Security
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Hey guys, I created an account on here just to post to this thread. I was having this same problem, SFC would not complete due to these Windows Defender/MSE files having an issue. I ran the Eset Sirefef remover tool with the /r option and it was able to fix the issue with these files. SFC now completes (It actually didn't even need to complete to fix my overall issue, once these files were repaired, my main issue was resolved).

Just wanted to say thanks, I've been working this for hours.
 

My Computer My Computer

At a glance

Windows 7 Pro 32
Computer type
PC/Desktop
OS
Windows 7 Pro 32
Nice to know. May I ask how exactly you found this thread? What were the google search words, if you remember?

The reason I ask is it seems Google can prioritize hot threads for a certain issue in real time, even parsing the content for exactness.
 
I searched for:

STATUS_FILE_IS_A_DIRECTORY cbs.log
 

My Computer My Computer

At a glance

Windows 7 Pro 32
Computer type
PC/Desktop
OS
Windows 7 Pro 32
So google is indexing our content in real time. Good. Many don't know that John works on this constantly and is one key to the Forums' smashing success.

This helps countless thousands who are savvy enough to type in the error text, or even deftly describe the issue.

It also causes our threads to live on forever, which is why they've never closed and deserve updating even if you come across a really old one.
 
Thx guys - ESET Sirefef Cleaner worked so SFC can run again now.

Fett: I found it with the same query ;)
 

My Computer My Computer

At a glance

Windows 7ATI 3470
OS
Windows 7
Graphics Card(s)
ATI 3470
Back
Top