PDA

View Full Version : Help Virus.



MrToxicCodes
July 20th, 2012, 12:57 PM
I download my message in txt,mxl,cvs form and no i got this virus in my computer

"C:\Users\Toxic\AppData\Local\Google\Chrome\Application\chrome.exe (2344)";"Found Luhe.Sirefef.A"

there was 2 of them and avg was able to clean 1 one only please help i need this gone

57009
57010

chevy350
July 20th, 2012, 01:20 PM
Have you tried using malwarebytes? May have to scan in safe mode, noticed it say's something about memory......

_Deano_
July 20th, 2012, 01:20 PM
Download Malwarebytes Do a Full Scan http://www.malwarebytes.org/

MrToxicCodes
July 20th, 2012, 01:30 PM
Man Im running malawarebytes,trend micro housecall, and im installing spyhunter as we speak. I called avg for support and they want more money just to tell me what kind it is. So i hope one of these programs will remove it. I been doin research on the virus itself
this is a good link i found
http://www.2-viruses.com/remove-sirefef
i will let you all know if it works. if not ill restore my computer

chevy350
July 20th, 2012, 01:52 PM
I would try seeing which one of those scanners you can run in safe mode and see it that helps before doing a restore.

MrToxicCodes
July 20th, 2012, 02:36 PM
I would try seeing which one of those scanners you can run in safe mode and see it that helps before doing a restore.

Ok Ill try that if none of these scans detects and destorys. Cause im sure its the one file in the image i provided that its the virus since it wont give me access to it. I tried to take ownership of it and still no.

Big V
July 20th, 2012, 02:38 PM
Well even a restore is not always helpful bud because some of these nasty little buggers like to self replicate themself once they have gotten on your system and a restore will not clean it

My best advice once you get this solved get rid of avg and get a real antivirus. Anymore avg has sunk to the same level of worthlessness that norton antivirus is known for in my opinion

Their a reason why it a free antivirus bud because it doesn't protect you from crap

MrToxicCodes
July 20th, 2012, 02:48 PM
Well even a restore is not always helpful bud because some of these nasty little buggers like to self replicate themself once they have gotten on your system and a restore will not clean it

My best advice once you get this solved get rid of avg and get a real antivirus. Anymore avg has sunk to the same level of worthlessness that norton antivirus is known for in my opinion

Their a reason why it a free antivirus bud because it doesn't protect you from crap

What would you recomend? That really works and does it job? That easy to understand like firewall settings and stuff? And pro vs cons

twizzz
July 20th, 2012, 02:59 PM
My advice as a malware removal specialist.. (As in this is what i do everyday for a living).. If you have run malwarebytes and you still have this in the Chrome directory would be to uninstall Chrome and delete all files and folders dealing with it.. Run this .. The Emsisoft Free Emergency Kit... (This is one hell of a powerful malware removal tool)... When you finish the full scan... Follow up with Hitman Pro to see if theres any sorta remaining junk... If so you might wanna download and run a bootable anti virus something like Kaspersky's Rescue Disk... Ill leave the links below..
Emsisoft Free Emergency Kit... http://www.emsisoft.com/en/software/eek/
Hitman Pro... http://www.surfright.nl/en
Kaspersky Rescue Disk... http://support.kaspersky.com/faq/?qid=208282173

Hope this helps you.. If not let me know ..

MrToxicCodes
July 20th, 2012, 03:04 PM
Ok so here a update so far. I used spybot search and destory it came up with stuff from searchbars which is usall. But malawarebytes keeps block
port: some random number svchost.exe from internet? anyone know what this means

MrToxicCodes
July 20th, 2012, 03:05 PM
My advice as a malware removal specialist.. (As in this is what i do everyday for a living).. If you have run malwarebytes and you still have this in the Chrome directory would be to uninstall Chrome and delete all files and folders dealing with it.. Run this .. The Emsisoft Free Emergency Kit... (This is one hell of a powerful malware removal tool)... When you finish the full scan... Follow up with Hitman Pro to see if theres any sorta remaining junk... If so you might wanna download and run a bootable anti virus something like Kaspersky's Rescue Disk... Ill leave the links below..
Emsisoft Free Emergency Kit... http://www.emsisoft.com/en/software/eek/
Hitman Pro... http://www.surfright.nl/en
Kaspersky Rescue Disk... http://support.kaspersky.com/faq/?qid=208282173

Hope this helps you.. If not let me know ..

Are these free? Or they a free scan but to fix you have to pay?

twizzz
July 20th, 2012, 03:08 PM
They are free... And svchost.exe you see there is a service host most likely dealing with Windows itself.. Something from Microsoft... Might be a case of a false positive.. Which means you have nothing to worry about when you see that..

MrToxicCodes
July 20th, 2012, 03:11 PM
They are free... And svchost.exe you see there is a service host most likely dealing with Windows itself.. Something from Microsoft... Might be a case of a false positive.. Which means you have nothing to worry about when you see that..

I was just wondering cause everytime it was a different port number. and a different website id or ip idk wat u call it

twizzz
July 20th, 2012, 03:18 PM
Yes it looks odd and maybe looks somewhat like a malware downloader via a net viewer. However its doing nothing more then phoning home to certain microsoft servers.. You have to remember a default Windows 7 machine will run up to 15 service host (or svchost.exe) at anyone time.. What you are seeing are anyone of those 15 phoning home.. They all look the same but there differnt processes..

MrToxicCodes
July 20th, 2012, 03:27 PM
57012

jkd
July 20th, 2012, 03:32 PM
Use bittdefender total security, here is a 90 day trail total bitdefender 2013 http://www.downloadcrew.com/article/27729-bitdefender_total_security. It's what i use and is acclaimed to be the best antivirus program check reviews.

Good luck.

gor17981
July 20th, 2012, 04:55 PM
+1for bit defender here, been using it for a long time, at least 2 or 3 year now, never had any issues since using it. highly reccomended!! :Smile:

MrToxicCodes
July 20th, 2012, 05:46 PM
+1for bit defender here, been using it for a long time, at least 2 or 3 year now, never had any issues since using it. highly reccomended!! :Smile:

Ok everyone i ran through all my scans took about 5 hours for 4 scans at the same time all came clean except avg which came up with this place

"";"C:\Users\Toxic\AppData\Local\Google\Chrome\Application\chrome.exe (5600):\memory_01440000";"Found Luhe.Sirefef.A";"Infected"

So i installed TrendMicro HiJack this to delete the file after reboot then ima uninstall google chrome and everything that deals with it then maybe my computer will be clean.

Ill keep everyone updated

MrToxicCodes
July 20th, 2012, 08:43 PM
Ok everyone well after about 5-7 hours i think my computer finished scans and rebooted and everything and i deleted everything that dealt with chrome. It worked i dotn see any signs of the virus anymore thanks for all the help everyone i really do thank you

twizzz
July 20th, 2012, 09:02 PM
Sweet glad you got it cleaned.. I noticed you posted a screen shot of your task manager... To see all the service host running youll have to click show process from all users... Me i personally use Comodo Internet Security.. However im a huge fan of hips programs they are in the end the best form of protection when it comes to malware because these days its about what you call zero day malware.. Just a regular av engine cant catch everything out there ... If theres been no definition written for the malicious software the scan wont find it and you have to wait for it to be found.. Uploaded to the vender written into a def. and updated to your AV protection.. I know most people dont care so much for HIP's programs pop ups telling you whats going on.. But for me i like to know whats tryin to install on my machine... Maybe you should give Comodo a test run.. It's completely cant hurt and you might like it.. Juss a thought

MrToxicCodes
July 20th, 2012, 11:38 PM
Hey everyone thanks for all the help. I know this isnt a forum about computer protection and stuff. Its about customizing windows. I really do like to say thanks everyone. Hopefull this thread will stay here incase another person has this problem.

But i rebooted windows on my computer to be on the safe side