Win32/Sirefef on my PC

Hello, I am new to this form. My computer too is infected with the win32. Alerts kept popping up, I have ran malware scanners and removed it but it keeps coming back.

I have downloaded Combofix but have not run it because I dont want to do any additional damage? Any help would be appreciated

Thanks

Follow the instructions as stated on the website in my signature.

I dont see any instructions on the website

hey please follow this guide and attach your logs.

http://forum.avast.com/index.php?topic=53253.0

a malware expert will help you from there it might take a few hours.

Click on the link in my signature then click om remove malware.

I ran the OTL and then the aswMBR and have attached the logs. I really appreciate the help.

I can also attach logs from malwarbytes and rougekiller if you would like

Thanks

more attachments

malwarbytes log

Could you attach the RogueKiller logs please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL IE - HKU\S-1-5-21-1993962763-789336058-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=109935&babsrc=HP_ss&mntrId=8822db0b00000000000000219b139b9f IE - HKU\S-1-5-21-1993962763-789336058-1801674531-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=109935&babsrc=SP_ss&mntrId=8822db0b00000000000000219b139b9f IE - HKU\S-1-5-21-1993962763-789336058-1801674531-1003\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb_031&u=610CAF88E2878EB038E4484FC8C6A556&q={searchTerms} FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.order.1: "Search the web (Babylon)" FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=109935&babsrc=HP_ss&mntrId=8822db0b00000000000000219b139b9f" FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=109935&babsrc=KW_ss&mntrId=8822db0b00000000000000219b139b9f&q=" FF - prefs.js..searchreset.backup.browser.search.defaultenginename: "Blekko" FF - prefs.js..browser.startup.homepage: " " FF - prefs.js..searchreset.backup.keyword.URL: "http://blekko.com/ws/?source={SourceID}&tbp=url&toolbarid=blekkotb_031&u=USERGUID&q=" [2012/06/04 15:28:52 | 000,002,313 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012/06/01 09:42:19 | 000,002,134 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\search.xml O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present [2012/07/26 20:04:59 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Joe\Application Data\a159dde [2011/12/17 18:19:14 | 000,014,682 | --S- | C] () -- C:\Documents and Settings\Joe\Local Settings\Application Data\exguj6wj85bm217fl644yl2b73p7e [2011/12/17 18:19:14 | 000,014,682 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\exguj6wj85bm217fl644yl2b73p7e

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

running the otl right now (its on a diff pc)

here is the log from rougekiller earlier today

OTL seems to have froze up says (NOT RESPONDING) on screen… ?? wait or restart?

Stop OTL and continue to Combofix please

atl+ctrl+del wont do anything should I pull the plug on the machine?

What does OTL say at the bottom ?

Does clicking the X work ?

If not then hard reboot by powering off

Here is the combofix log file

Had to restart the computer during OTL when it froze.

Thank you for your help

Are you still getting Avast alerts ?

I have it disabled right now i will rerun

just ran a quick scan on avast and came back with 0…

Any further problems before I remove my tools ?

went to restart computer got a blue screen saying dumping physical memory