SFC Scannow
It's Borked!!
Tuesday, October 8, 2013 by RedneckDude | Discussion: Personal Computing
Hey guys, anyone ever have SFC Scannow to fail?
I had a virus yesterday, got it fixed, but now I get this error when I try to run SFC Scannow on Windows 8 Pro MCE.
It always fails at 64%.

Reply #22 Wednesday, October 9, 2013 12:20 PM
If you'll read further, you see I did say what it was and how I fixed it.
No A/V catches everything.
Reply #23 Wednesday, October 9, 2013 12:24 PM
Well, all scan show I'm now clean, but it looks like maybe a format and reinstall may be in order.
Could blow in a backup, but I'm also having a disk check every boot.

Reply #24 Wednesday, October 9, 2013 5:14 PM
trojan.sirefef.gy is packed with Zeroaccess !!!
its just a different name used by the AV-company of your AV
http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
http://en.wikipedia.org/wiki/ZeroAccess_botnet
http://www.trojaner-board.de/119680-trojan-sirefef-gy-eingefangen-tun.html
its in german they point out that you should stay offline change online banking passwords on a different computer even if it looks clean they recommend a clean install.
sorry RND I must have been blind...
didnt see trojan.sirefef.gy but then i wasnt to far of since both are the same with a different name
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...
No A/V catches everything.
What i ment with that is that if a "trojan" manages to create a folder without beeing detected it isnt average class "medium" normaly these things get stopped right away i know that no AV catches every intruder no offense ment...
I would do the same
this is a backdoor trojan with rootkit functionality RND.. no matter how hard you clean you will break stuff or have dirty little remainings on your system
+ the Danger of beeing ripped off and keylogged in the worst case..
Reply #25 Wednesday, October 9, 2013 6:02 PM
I normaly do not make postings to "BUMP" but in this case i think it is wise because i dont know if MR. RND/JIM uses online Banking
IF someone has his contact inform him kindly TY
OH and BUMP!
Reply #26 Wednesday, October 9, 2013 6:08 PM
I do use online banking. I appreciate your efforts.
I am probably gonna just do a fresh install. I have had problems ever since swapping OSes to opposite drives anyway.
Reply #27 Wednesday, October 9, 2013 6:12 PM
good choice glad you have seen this in time... now get offline and change your passwords if you can!
And have a good night its past midnight here and i have school tomorrow [e digicons]:')[/e]
Reply #28 Thursday, October 10, 2013 9:55 PM
OK, upon reinstall of both OSes. Having saved sig bins for all SD apps. The new install of CursorFX will not activate. Someone please reset my activations?
Reply #29 Friday, October 11, 2013 2:43 AM
Thats prob because your SID changed...
http://widget00.mibbit.com/?settings=2f03189799dc83fa3ecd3362e8912c06&server=irc.stardock.com&channel=%23stardock
Fastest way to have that solved...
Reply #32 Friday, October 11, 2013 9:37 PM
Quoting RedneckDude, reply 28
OK, upon reinstall of both OSes. Having saved sig bins for all SD apps. The new install of CursorFX will not activate. Someone please reset my activations?
Jim, please fire off a quick email to support.
Reply #33 Friday, October 11, 2013 9:37 PM
Quoting RedneckDude, reply 15KasperskyTDSSkiller, then ComboFix.
2 invaluable tools in any windows tool box!
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #21 Wednesday, October 9, 2013 8:34 AM
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...in this last case i would not just sit back and cross my fingers that everything is fine
Not to mention that this is a very strange place for a trojan to settle...
All i read was that the problem is fixed but could you provide a bit more info on how you fixed it and what was found?
If you do not know the name i have one for you that is related to that folder its called Tr.Zaccess/Zeroaccess
...could be a trojan / or a rootkit
Edit just read more about it:
https://forums.malwarebytes.org/index.php?showtopic=133003
before you look through the log
make a search on the page if you like ( CTRL + F ) not type systemroot\system32
something like that should be highlighted as text
[ZeroAccess][Junction] en-US : C:\Program Files\Windows Defender\en-US >> \systemroot\system32\config [-] --> FOUND
That is BAD!