Struggling with Win32:Sirefef-PL

Evening,

I’ve picked up some sort of ‘Win32:Sirefef-PL [Rtk]’ infection. Between Malawarebytes, Tdsskiller, and Avast! I can usually rid myself of anything that comes up, but this one seems nasty. So I would appreciate some help.

Questions answered in order from the sticky.

  1. Blocked first as Infection: Win32:Downloader-PKU [Trj]. Win32:Sirefef-PL [Rtk] detected in scanning. Can be deleted but returns as Trojan Horse Block repeatedly.
  2. Unsure. Using Chrome. Browsing Tour de France streams.
  3. Possibly fake flash install.
  4. Infection: Win32:Downloader-PKU [Trj]. Object: c:\Windows\Installer.…\80000032.@. Action: Moved to chest. Process: C:\Windows\System32\services.exe

Thanks in advance for your help.

James

follow this guide and attach (not copy and paste) logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

when done a malware remover will be notified: It may take sveral hours before one arrive so be patient

Hi,

I will look these over when they arrive. :slight_smile:

Thanks for your speedy replies.
Logs attached.
Just so you know, I won’t be back with my machine for another 12-14 hours today.

OTL / aswMBR logs are coming…

OTL logs

MBR logs attached.

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

Note: It is important that it is saved directly to your desktop
If you get a message saying “Illegal operation attempted on a registry key that has been marked for deletion”, please restart your computer.


IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here


Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
[*]Please post the C:\ComboFix.txt for further review.

Thanks for your continued assistance.

Combofix downloaded direct to desktop.

(should have added I’ll post reports later - after 5pm BST)

Not a problem. No hurry. :slight_smile:

One quick question, am I advised to turn wifi (and hence internet) off before disabling antivirus/antispyware software and launching ComboFix? My instinct would be to turn off wifi to stop anything else getting in whilst antivirus/antispyware software is disabled. But I’m, of course, happy to follow you lead on this.

You should just disable your antivirus program and firewall while running ComboFix. Don’t worry about the internet. :slight_smile:

Okay. Thanks.

No problem.

I have right-clicked and run ComboFix as an admin, but, as far as I can see, ComboFix is not returning a .txt report.
Please advise.

To update, I’ve tried again and this time ComboFox rebooted the machine with the status bar at just over halfway (rather than just going to the end and disappearing), and is now running a process on a blue screen (which seems more promising).

Ok just let it run… :slight_smile:

We are done! ComboFix report attached as promised.

Hi,

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.

Please run a free online scan with the ESET Online Scanner
[i]Note: You will need to use Internet Explorer for this scan[/i]
[*]Tick the box next to YES, I accept the Terms of Use
[*]Click Start
[*]When asked, allow the ActiveX control to install
[*]Click Start
[*]Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
[*]Click Scan (This scan can take several hours, so please be patient)
[*]Once the scan is completed, you may close the window
Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner[b]log.txt
[*]Copy and paste that log as a reply to this topic


Download Security Check by screen317 from here or here.
[*]Save it to your Desktop.[*]Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.[*]A Notepad document should open automatically called checkup.txt; please post the contents of that document.