Just my thoughts....
It's Borked!!
Published on October 8, 2013 By RedneckDude In Personal Computing

Hey guys, anyone ever have SFC Scannow to fail?

 

I had a virus yesterday, got it fixed, but now I get this error when I try to run SFC Scannow on Windows 8 Pro MCE.

 

It always fails at 64%.

 

 


Comments (Page 2)
3 Pages1 2 3 
on Oct 08, 2013

RedneckDude
Seems all is well, at the moment.

Jafo crosses fingers...

on Oct 08, 2013

Thanks Jafo. Now, if only I knew where I got the virus....

 

I'm guessing an infected site, maybe even facebook. It settled in the Google folder, so I was probably using Chrome at the time?

on Oct 09, 2013

I've been to FB on and off. Do you have the HTTPS installed?

on Oct 09, 2013

RedneckDude


Quoting DrJBHL, reply 5Can you try after C:\Windows\system32> enter c: and then 'enter'
You should get
C:\>

 

No, I get C:\Windows\system32> again

 

 

 in Windows you use:

cd c:\

 

 

on Oct 09, 2013

RedneckDude
Thanks for the help, Doc.

You're welcome Jim.

on Oct 09, 2013

 the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...in this last case i would not just sit back and cross my fingers that everything is fine
Not to mention that this is a very strange place for a trojan to settle...

All i read was that the problem is fixed but could you provide a bit more info on how you fixed it and what was found?

If you do not know the name i have one for you that is related to that folder its called Tr.Zaccess/Zeroaccess
...could be a trojan / or a rootkit

Edit just read more about it:
https://forums.malwarebytes.org/index.php?showtopic=133003

before you look through the log
make a search on the page if you like ( CTRL + F ) not type systemroot\system32

something like that should be highlighted as text 
[ZeroAccess][Junction] en-US : C:\Program Files\Windows Defender\en-US >> \systemroot\system32\config [-] --> FOUND

That is BAD! 

 

on Oct 09, 2013

Roloccolor
All i read was that the problem is fixed but could you provide a bit more info on how you fixed it and what was found?

 

If you'll read further, you see I did say what it was and how I fixed it.

 

 

Roloccolor
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...

No A/V catches everything.

on Oct 09, 2013

 

 

 

Well, all scan show I'm now clean, but it looks like maybe a format and reinstall may be in order.   

 

 

Could blow in a backup, but I'm also having a disk check every boot.  

 

 

 

 

 

 

 

 

on Oct 09, 2013

trojan.sirefef.gy is packed with Zeroaccess !!!  

its just a different name used by the AV-company of your AV
http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
http://en.wikipedia.org/wiki/ZeroAccess_botnet

http://www.trojaner-board.de/119680-trojan-sirefef-gy-eingefangen-tun.html
its in german they point out that you should stay offline change online banking passwords on a different computer even if it looks clean they recommend a clean install.
 

sorry RND I must have been blind...    didnt see trojan.sirefef.gy but then i wasnt to far of since both are the same with a different name

RedneckDude
Quoting Roloccolor, reply 21
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...
No A/V catches everything.

What i ment with that is that if a "trojan" manages to create a folder without beeing detected it isnt average class "medium" normaly these things get stopped right away i know that no AV catches every intruder no offense ment...


RedneckDude
Well, all scan show I'm now clean, but it looks like maybe a format and reinstall may be in order.  

I would do the same
this is a backdoor trojan with rootkit functionality RND.. no matter how hard you clean you will break stuff or have dirty little remainings on your system
+ the Danger of beeing ripped off and keylogged in the worst case.. 

 

on Oct 09, 2013

I normaly do not make postings to "BUMP" but in this case i think it is wise because i dont know if MR. RND/JIM uses online Banking
IF someone has his contact inform him kindly TY
OH and BUMP! 

on Oct 09, 2013

I do use online banking. I appreciate your efforts.

 

I am probably gonna just do a fresh install. I have had problems ever since swapping OSes to opposite drives anyway.

on Oct 09, 2013

 good choice glad you have seen this in time... now get offline and change your passwords if you can!
And have a good night its past midnight here and i have school tomorrow [e digicons]:')[/e]  

on Oct 10, 2013

OK, upon reinstall of both OSes. Having saved sig bins for all SD apps. The new install of CursorFX will not activate. Someone please reset my activations?

on Oct 11, 2013

Thats prob because your SID changed... 
http://widget00.mibbit.com/?settings=2f03189799dc83fa3ecd3362e8912c06&server=irc.stardock.com&channel=%23stardock
Fastest way to have that solved...
 

on Oct 11, 2013

RedneckDude

OK, upon reinstall of both OSes. Having saved sig bins for all SD apps. The new install of CursorFX will not activate. Someone please reset my activations?

Jim, please fire off a quick email to support.

3 Pages1 2 3