Author Topic: Struggling with Win32:Sirefef-PL  (Read 14324 times)

0 Members and 1 Guest are viewing this topic.

kykiske

  • Guest
Struggling with Win32:Sirefef-PL
« on: July 23, 2012, 12:40:21 AM »
Evening,

I've picked up some sort of 'Win32:Sirefef-PL [Rtk]' infection. Between Malawarebytes, Tdsskiller, and Avast! I can usually rid myself of anything that comes up, but this one seems nasty. So I would appreciate some help.

Questions answered in order from the sticky.

1) Blocked first as Infection: Win32:Downloader-PKU [Trj]. Win32:Sirefef-PL [Rtk] detected in scanning. Can be deleted but returns as Trojan Horse Block repeatedly.
2) Unsure. Using Chrome. Browsing Tour de France streams.
3) Possibly fake flash install.
5) Infection: Win32:Downloader-PKU [Trj]. Object: c:\Windows\Installer\...\80000032.@. Action: Moved to chest. Process: C:\Windows\System32\services.exe

Thanks in advance for your help.

James

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Struggling with Win32:Sirefef-PL
« Reply #1 on: July 23, 2012, 12:54:59 AM »
follow this guide and attach (not copy and paste) logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

when done a malware remover will be notified: It may take sveral hours before one arrive so be patient

jeffce

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #2 on: July 23, 2012, 01:10:10 AM »
Hi,

I will look these over when they arrive.  :)

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #3 on: July 23, 2012, 10:15:41 AM »
Thanks for your speedy replies.
Logs attached.
Just so you know, I won't be back with my machine for another 12-14 hours today.

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #4 on: July 23, 2012, 10:20:09 AM »
OTL / aswMBR logs are coming...

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #5 on: July 23, 2012, 10:39:49 AM »
OTL logs

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #6 on: July 23, 2012, 11:48:06 AM »
MBR logs attached.

jeffce

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #7 on: July 23, 2012, 08:46:20 PM »
Download Combofix from either of the links below, and save it to your desktop. 
Link 1
Link 2

**Note:  It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the C:\ComboFix.txt for further review.

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #8 on: July 23, 2012, 11:56:06 PM »
Thanks for your continued assistance.

Combofix downloaded direct to desktop.

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #9 on: July 24, 2012, 08:29:57 AM »
(should have added I'll post reports later - after 5pm BST)

jeffce

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #10 on: July 24, 2012, 01:55:11 PM »
Not a problem.  No hurry.  :)

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #11 on: July 24, 2012, 02:09:40 PM »
One quick question, am I advised to turn wifi (and hence internet) off before disabling antivirus/antispyware software and launching ComboFix? My instinct would be to turn off wifi to stop anything else getting in whilst antivirus/antispyware software is disabled. But I'm, of course, happy to follow you lead on this.

jeffce

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #12 on: July 24, 2012, 02:15:16 PM »
You should just disable your antivirus program and firewall while running ComboFix.  Don't worry about the internet.  :)

kykiske

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #13 on: July 24, 2012, 02:16:29 PM »
Okay. Thanks.

jeffce

  • Guest
Re: Struggling with Win32:Sirefef-PL
« Reply #14 on: July 24, 2012, 02:21:12 PM »
No problem.