Author Topic: Win32:sirefef-Pl [Rtk] Question  (Read 1172 times)

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Win32:sirefef-Pl [Rtk] Question
« on: July 04, 2012, 11:37:11 PM »
Ok I was surfing, clicked on a page, and then Avast blocked a trojan and moved it to sandbox, Avast said it didn't harm my computer, but I ran a scan. It came out clean, but I ran a boot scan JIC, and it found the Sirefef virus. I tossed it in the chest, ran a couple of more scans and it says everything is clear. I just wanted to double check and see if there is everything else I needed to do.

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #1 on: July 04, 2012, 11:47:46 PM »
I looked for the log  and can't find it, but I took a screen shot, hope this helps. Also, I have not experienced any problems like popups or crashes, Avast said it blocked it, and everything seems fine I am just checking to make sure I don't have a problem.

Offline Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17064
  • Gender: Male
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #2 on: July 04, 2012, 11:56:28 PM »
if you suspect infection.....go to the virus and worms section...create a topic where you attach the logs from this guide
http://forum.avast.com/index.php?topic=53253.0
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #3 on: July 05, 2012, 02:18:23 AM »
I did run malwarebytes and it said it is clean, so that and avast saying it is clean (boot scan and deep scan) I think everything is ok. I guess I am being paranoid. Would that otl do anything that might verify that the other two are right?

Online iroc9555

  • avast! Evangelist
  • Massive Poster
  • ***
  • Posts: 3292
  • Gender: Male
  • CCS, Vzla.
    • Personal Message (Online)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #4 on: July 05, 2012, 02:23:16 AM »
OTL and aswMBR will indicate if you're still infected. So follow Pondus advice and attach logs for those programs. A qualify malware remover will take a look and tell you what to do.
Hernan.
Dim 9200/XPS 410. C2D E6600; 2.40 GHz; 2 GB SDRAM. XP Pro_86. Spk3. IE 8 & FF 21. Avast! FREE 8.0.1489. CIS 5.12(Fw/D+). MBAM Pro. SpywareBlaster. WinPatrol + . WOT. SAS Pro (O/D).
“We are all ignorant, but we don't all ignore the same things..” Albert Einstein.

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #5 on: July 05, 2012, 02:38:46 AM »
ok here is OTL scan

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #6 on: July 05, 2012, 02:48:19 AM »
and here is the other scan. I did the quick scan, and then one for drive C which I thought might be a deep scan?? anyway here they are.

Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #7 on: July 05, 2012, 02:48:51 AM »
and the quick scan

Online iroc9555

  • avast! Evangelist
  • Massive Poster
  • ***
  • Posts: 3292
  • Gender: Male
  • CCS, Vzla.
    • Personal Message (Online)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #8 on: July 05, 2012, 02:54:33 AM »
Thanks. A malware analist will be notified. Mind you that it is really late in EU and 4 th of July in the USA so it will not be until tomorrow that you can have an answer.
« Last Edit: July 05, 2012, 03:04:10 AM by iroc9555 »
Hernan.
Dim 9200/XPS 410. C2D E6600; 2.40 GHz; 2 GB SDRAM. XP Pro_86. Spk3. IE 8 & FF 21. Avast! FREE 8.0.1489. CIS 5.12(Fw/D+). MBAM Pro. SpywareBlaster. WinPatrol + . WOT. SAS Pro (O/D).
“We are all ignorant, but we don't all ignore the same things..” Albert Einstein.

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #9 on: July 05, 2012, 01:24:22 PM »
Looks good, The detections in the bootscan were of Avast signatures ...  So you dodged the bullet  ;D



Offline the_airwarrior

  • Newbie
  • *
  • Posts: 11
    • Personal Message (Offline)
Re: Win32:sirefef-Pl [Rtk] Question
« Reply #10 on: July 05, 2012, 08:28:22 PM »
thanks  essex I wanted to make certain as the more I read about this thing it is a nasty little booger! thanks to iroc and Pondus too!