TeamRocketOps wrote:MSE goes into infinite loop when it detects infected services.exe AFTER partial removal.
This is correct. MSE fails to remove Sirefef.Y and this is also why you can find MSE's 50,000byte system driver stuck in Drivers section of logs.
Examples (caused by multiple removal fail by MSE)
Code: Select all1 axqvsxde; \??\C:\Windows\system32\drivers\axqvsxde.sys [x]
1 beaxgerf; \??\C:\Windows\system32\drivers\beaxgerf.sys [x]
1 epvwbckj; \??\C:\Windows\system32\drivers\epvwbckj.sys [x]
1 feetgaza; \??\C:\Windows\system32\drivers\feetgaza.sys [x]
1 hmhdbcgf; \??\C:\Windows\system32\drivers\hmhdbcgf.sys [x]
1 ofdtudxb; \??\C:\Windows\system32\drivers\ofdtudxb.sys [x]
1 sgfntmwz; \??\C:\Windows\system32\drivers\sgfntmwz.sys [x]
1 tgcxrtzb; \??\C:\Windows\system32\drivers\tgcxrtzb.sys [x]
1 urpvvzux; \??\C:\Windows\system32\drivers\urpvvzux.sys [x]
Source:
http://forums.majorgeeks.com/showthread.php?t=260387