Infected by Win32:sirefef-FQ

Hi Greg,

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste


del "C:\Users\Greg\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\120324022601300.rsc"

Press Enter
Now close the Command Prompt

How is your system running now? :slight_smile:

My system seems to be running okay.

I am still having a couple of problems with the ESET NOD32 antivirus component on my system. I am unable to use the interface and it continually prompts me that it is unable to communicate with the “kernal”. I dont know if this is to do with the virus.

Besides this everything is running smoothly. :slight_smile:

Hi,

Let’s get a new scan with OTL and attach the new log so we can get a fresh look.

okay, thankyou very much. Here is the log.

Hi,

Run OTL.exe

[*]Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL


:Services

:OTL
IE - HKU\S-1-5-21-2719949982-2696988471-487218896-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 79 C8 28 DE 79 1C CB 01  [binary data]
IE - HKU\S-1-5-21-2719949982-2696988471-487218896-1001\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
[2011/07/08 04:04:23 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\tfhhn7o0.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O4 - Startup: C:\Users\Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NetTools.lnk =  File not found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-itss - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O28 - HKLM ShellExecuteHooks: UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot when it is done
[*]Then run a new scan and post a new OTL log ( don’t check the boxes beside LOP Check or Purity this time )


Attatched are the two logs produced. Upon system restart, after running the OTL fix, my system seemed unable to boot. After a number of attempts the loading screen finally appeared and the system booted as normal. I wasnt sure if this was to do with the fix or whether it had just overheated :slight_smile: .

Hi,

Any improvements? :slight_smile:

I have had no further problems when booting my system although I have recently had my system crash a couple of times when running pretty standard applications or processes, i.e. internet browser. Again i did wonder if this was just down to overheating and the need for abit of fan cleaning.

With regards to ESET it still seems to be having problems, prompting me that it cannot communicate with the kernal, however i think the best/easiest fix would perhaps be to re-install it :slight_smile:

I haven’t noticed any more symptoms/problems to do with the original virus, but then again I’m no expert :).

Yeah I was going to have you reinstall ESET if you were still having problems with it and see if that fixed it up. :slight_smile: