Author Topic: Infected: win32:Sirefef-PL [Rtk] - Help Please  (Read 19402 times)

0 Members and 1 Guest are viewing this topic.

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #15 on: July 27, 2012, 08:29:36 PM »
I am still having problems updating programs. This utility is great but it hasn't fixed the update from opening in Word. Aside from this does everything seem clean as far as my system goes? Should I remove all of these programs that I installed for the purpose of this testing?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #16 on: July 27, 2012, 09:03:56 PM »
What I will do is remove the programmes that we have used, tidy you up and then look at the association problems..

On that front is it all exe programmes that open in word or just ones downloaded from the web.  Or is it that the auto updates instead of going to the website to download open a word document ?

If it is the later there is a link to a reg file at the end with installation instruction

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK



  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Go to control panel
  • Select folder options (Appearance > Folder options in category view)
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
SPRING CLEAN

To manually create a new Restore Point
 
  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • GoStart > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.  Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?

Keep safe  :wave:


Reg file link https://dl.dropbox.com/u/73555776/Default_LNK_%28Shortcut%29.reg
Download to the desktop
Right click and select merge
Accept the warnings
Reboot and try an update again

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #17 on: July 27, 2012, 10:22:01 PM »
Essexboy,

You have been incredibly helpful and it is extremely appreciated! I have completed all of the steps in your previous post. I downloaded Filehippo update checker and when I ran it the 4 updates it recommended for me were opened into a word document-I am going to attempt to attach the word file that I saved as a webpage to this post. It seems to be only programs I have downloaded from the web, at least that is all I have noticed. Any ideas? I did not do the last step of your previous post since I was not sure if it was fitting to my situation. Thank you.

*Edit: file was too large to attach

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #18 on: July 27, 2012, 11:06:40 PM »
Yes run that association fix and see if it cures it

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #19 on: July 29, 2012, 09:55:01 PM »
Sorry but I am unsure how to download the file you posted. The link is simply a bunch of text within the website and if I save link as it is merely a text file on my desktop. Sorry for my ignorance here, but how am I supposed to get that into the registry?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #20 on: July 29, 2012, 10:12:05 PM »
OK right click the link and select save as..

Save it to your desktop
Right click the file and select merge
Acept any warnings

Rebbot

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #21 on: July 30, 2012, 12:46:09 AM »
Ah OK. I merged it and rebooted but updates continue to open in word documents? I am attaching a printscreen of what opened when I clicked to update my Glary Utilities. Any other ideas? Sorry this is being so pesky.

Edit: png was too large so I guess that part of this post is out.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #22 on: July 30, 2012, 04:25:59 PM »
Have you been using a registry cleaner as your associations appear to be totally skewed

There are association reg fixes here http://www.winhelponline.com/blog/file-asso-fixes-for-windows-7/ 

I would recommend that you run the main ones initially but do include the HTML one

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #23 on: August 03, 2012, 06:52:00 AM »
Hey Essexboy,

Sorry I have not replied for a few days, I just finished a 1700 mile road trip back home. I have run the majority of the reg fixes and and merged them. However, I still continue to have the problem. I have uploaded an image of the word document it opens to ImageShack and will try to post it here. Hopefully it works, again sorry for the delay!



Uploaded with ImageShack.us

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #24 on: August 03, 2012, 01:58:42 PM »
Please run the following tool, then try the updates

Please download exe_fix and save it to your desktop

Double click on exe_fix.com to run it.

Type the number 1 at the prompt and allow the tool to run

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #25 on: August 07, 2012, 12:45:03 AM »
Essexboy,

It merely saves as a text file to my desktop and opens as such. The only clear sentence in the file is that it must be run using Win32? I run 64 bit if that is what it is referring to? I am sorry if I do not understand the process you are asking me to do. I saved the link to my desktop in both txt and "all files" and neither ran in the manner which I expected it to (such as a normal exe would run) nor prompted me to type "1" as a command prompt.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #26 on: August 07, 2012, 05:28:11 PM »
When you download an exe file to the desktop and click it does it run ?

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #27 on: August 07, 2012, 05:46:29 PM »
When I right click to save link as it only gives me the options of a text file or "all files". However, I just tried to save it from the page during this post and it was able to save as a binary file. So I ran that but after opening a blue box it reported that "this tool is not compatible with your system" and to press any key to continue (I even tried pressing 1 here for the slim chance but no success). :( this is so frustrating.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #28 on: August 07, 2012, 07:06:23 PM »
Does this apply to all exe files that you put on your desktop

Gimmick

  • Guest
Re: Infected: win32:Sirefef-PL [Rtk] - Help Please
« Reply #29 on: August 07, 2012, 09:27:53 PM »
No. I dropped Ccleaner to my desktop from a separate folder and tried opening it and it opened just fine.