SFC Scannow

It's Borked!!

Hey guys, anyone ever have SFC Scannow to fail?

 

I had a virus yesterday, got it fixed, but now I get this error when I try to run SFC Scannow on Windows 8 Pro MCE.

 

It always fails at 64%.

 

 

74,698 views 33 replies
Reply #1 Top

Maybe the virus changed something in the registry or you didn't get all of the virus removed?   I'm just guessing here. 

Reply #2 Top

1. Are you running it as an Administrator? And, did you do it in "Safe Mode"? If not, do so.

2. Did you put in any MS 'Fixits' regarding the font exploit? http://technet.microsoft.com/en-us/security/bulletin/ms11-087

Deny access to T2EMBED.DLL That might be preventing SFC /scannow, although I remember that s failing at 15%, so I doubt it.

You could try booting to the installation dvd, select repair options. From there choose command prompt and run sfc.

3. You might also try to run chkdsk /f /r as an admin....again, from safe mode.

4. Is this an HDD or SSD? If it's a HDD can you check for 'immanent failure'?

5. You might check this: http://social.technet.microsoft.com/Forums/windows/en-US/52834d80-f863-43ac-8b65-fc71bd173f5e/sfc-scannow-fails-at-15?forum=w7itprogeneral


Did you do any of the things recommended in my article http://drjbhl.joeuser.com/article/448314/Some_Useful_Links_For_Windows_8_Users ?

 

Reply #3 Top

Quoting DrJBHL, reply 2
1. Are you running it as an Administrator?
End of DrJBHL's quote

Look at the screenshot.

 

2. No.

 

3. Done

4. SSD

5. I'll check.

 

I made the recovery drive flash drive.

Reply #4 Top

2. Isn't for Windows 8.

Reply #5 Top

Quoting RedneckDude, reply 3
I made the recovery drive flash drive.
End of RedneckDude's quote

So you have the recovery flash drive...have you used it?

What virus did you have and how did you fix it?

Can you try after C:\Windows\system32> enter c: and then 'enter'

You should get 

C:\>

now enter (immediately after the C:\>attrib –s –h *.* /S /D    There's a space between attrib and -s and -h and *.* and /S and /D

Which will unhide files which shouldn't have been hidden (and might have been by the virus) and make them readable and fixable.

Then try sfc /scannow in admin mode.

 

Reply #6 Top

Quoting DrJBHL, reply 5
So you have the recovery flash drive...have you used it?
End of DrJBHL's quote

No, I don't want to do a recovery. I don't want to lose all my programs, etc.

 

 

 

Reply #7 Top

Quoting DrJBHL, reply 5
Can you try after C:\Windows\system32> enter c: and then 'enter'
You should get
C:\>
End of DrJBHL's quote

 

No, I get C:\Windows\system32> again

 

Reply #8 Top

I'll probably do a repair install. But I had hoped for an easier fix.

 

 

 

Reply #9 Top

There's little question that you had a virus that reset things.

Did you look this virus up...and what it does, exactly - i.e. which settings it changes?

Which virus was it, Jim?

You can try this software to fix the effects of the virus [review of it] : http://www.ghacks.net/2010/02/09/recover-operating-system-after-virus-attack/

 

download here: http://sourceforge.net/projects/viruseffectremo/

 

Reply #10 Top

Quoting DrJBHL, reply 9
Did you look this virus up...and what it does, exactly - i.e. which settings it changes?
Which virus was it, Jim?
End of DrJBHL's quote

No Doc, all I know was it was a trojan and it resided in C:\Program Files (x86)\Google\Desktop.

 

Malwarebytes, and ASC Ultimate's Bit Defender A/V both claimed to quarantine it, but it kept coming back.

 

I had to boot into Win7, then browse to Win8  C:\Program Files (x86)\Google\Desktop and delete it.

Reply #11 Top

Actually, I am having a few other problems as well, like my mouse double clicking when it should be single clicking, and my PC runs a disk check at every reboot.

 

Considering a clean reinstall, if the repair install doesn't work.  X|

Reply #13 Top

You have to make sure it's gone, Jim. Don't you remember the name of the Trojan?

Once you have the name of the Trojan, you look it up on the net...especially at ESET and the antiviral software sites.

They generally have exact instructions as to how to remove it.

Do what they say before trying to repair effects.

Reply #14 Top

Quoting DrJBHL, reply 13
Do what they say before trying to repair effects.
End of DrJBHL's quote

Too late.

Reply #15 Top

OK, after looking up the virus, which was trojan.sirefef.gy,it said to run KasperskyTDSSkiller, then ComboFix. I did those, and cleaned what was found, then ran SFC scannow and it ran 100%. Found some stuff, and fixed them!

 

Seems all is well, at the moment.

 

Thanks for the help, Doc.

Reply #16 Top

Quoting RedneckDude, reply 15
Seems all is well, at the moment.
End of RedneckDude's quote

/me crosses fingers...;)

Reply #17 Top

Thanks Jafo. Now, if only I knew where I got the virus....

 

I'm guessing an infected site, maybe even facebook. It settled in the Google folder, so I was probably using Chrome at the time?

Reply #18 Top

I've been to FB on and off. Do you have the HTTPS installed?

Reply #19 Top

Quoting RedneckDude, reply 7


Quoting DrJBHL, reply 5Can you try after C:\Windows\system32> enter c: and then 'enter'
You should get
C:\>

 

No, I get C:\Windows\system32> again

 
End of RedneckDude's quote

 

 in Windows you use:

cd c:\

 

 

Reply #20 Top

Quoting RedneckDude, reply 15
Thanks for the help, Doc.
End of RedneckDude's quote

You're welcome Jim.

Reply #21 Top

 the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...in this last case i would not just sit back and cross my fingers that everything is fine
Not to mention that this is a very strange place for a trojan to settle...

All i read was that the problem is fixed but could you provide a bit more info on how you fixed it and what was found?

If you do not know the name i have one for you that is related to that folder its called Tr.Zaccess/Zeroaccess
...could be a trojan / or a rootkit

Edit just read more about it:
https://forums.malwarebytes.org/index.php?showtopic=133003

before you look through the log
make a search on the page if you like ( CTRL + F ) not type systemroot\system32

something like that should be highlighted as text 
[ZeroAccess][Junction] en-US : C:\Program Files\Windows Defender\en-US >> \systemroot\system32\config [-] --> FOUND

That is BAD! 

 

Reply #22 Top

Quoting Roloccolor, reply 21
All i read was that the problem is fixed but could you provide a bit more info on how you fixed it and what was found?
End of Roloccolor's quote

 

If you'll read further, you see I did say what it was and how I fixed it.

 

 

Quoting Roloccolor, reply 21
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...
End of Roloccolor's quote

No A/V catches everything.

Reply #23 Top

 

 

 

Well, all scan show I'm now clean, but it looks like maybe a format and reinstall may be in order.    :(

 

 

Could blow in a backup, but I'm also having a disk check every boot.   X|

 

 

 

 

 

 

 

 

Reply #24 Top

trojan.sirefef.gy is packed with Zeroaccess !!!  

its just a different name used by the AV-company of your AV
http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
http://en.wikipedia.org/wiki/ZeroAccess_botnet

http://www.trojaner-board.de/119680-trojan-sirefef-gy-eingefangen-tun.html
its in german they point out that you should stay offline change online banking passwords on a different computer even if it looks clean they recommend a clean install.
 

sorry RND I must have been blind... :\   didnt see trojan.sirefef.gy but then i wasnt to far of since both are the same with a different name

Quoting RedneckDude, reply 22
Quoting Roloccolor, reply 21
the folder ( C:\Program Files (x86)\Google\Desktop ) doesnt even exist on standart, if created by a trojan your AV must be out of date,lame or the attack above low budget...
No A/V catches everything.
End of RedneckDude's quote

What i ment with that is that if a "trojan" manages to create a folder without beeing detected it isnt average class "medium" normaly these things get stopped right away i know that no AV catches every intruder no offense ment... :blush:


Quoting RedneckDude, reply 23
Well, all scan show I'm now clean, but it looks like maybe a format and reinstall may be in order.  
End of RedneckDude's quote

I would do the same
this is a backdoor trojan with rootkit functionality RND.. no matter how hard you clean you will break stuff or have dirty little remainings on your system
+ the Danger of beeing ripped off and keylogged in the worst case.. 

 

Reply #25 Top

I normaly do not make postings to "BUMP" but in this case i think it is wise because i dont know if MR. RND/JIM uses online Banking
IF someone has his contact inform him kindly TY
OH and BUMP!