Author Topic: Sirefef-PL [rtk] infection-redirects and weak certificate errors  (Read 2101 times)

0 Members and 1 Guest are viewing this topic.

loadblok

  • Guest
First of all, thanks to the folks who volunteer to help the teaming masses, those yearning to be free of malware!

I have encountered Sirefef-PL [rtk] and it has rendered the PC *mostly* useless; google search results get redireced; and when attempting to access gmail I receive a warning about a weak certificate.  The address bar shows https with a red slash through it, and the padlock icon to he left of https has a red 'X' through it, and I am unable to access gmail.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sirefef-PL [rtk] infection-redirects and weak certificate errors
« Reply #1 on: July 31, 2012, 03:45:13 PM »
Hi you are being assisted by one of my students at GeeksToGo.  So I will let you continue there 
« Last Edit: July 31, 2012, 05:14:04 PM by essexboy »

loadblok

  • Guest
Re: Sirefef-PL [rtk] infection-redirects and weak certificate errors
« Reply #2 on: July 31, 2012, 05:42:09 PM »
Ran into trouble with ComboFix, it seemed to run normally to completion, then displayed a log, but when I try to open a browser or any program for that matter, I get a message stating, "Illegal operation has been attempted on a registry key that has been marked for deletion".  Affects all files, whether a simple text file or an executable.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: Sirefef-PL [rtk] infection-redirects and weak certificate errors
« Reply #3 on: July 31, 2012, 05:47:55 PM »
Just reboot again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

loadblok

  • Guest
Re: Sirefef-PL [rtk] infection-redirects and weak certificate errors
« Reply #4 on: July 31, 2012, 06:00:35 PM »
The PC seems to function better, am able to access gmail without the certificate error message.

Here are the OTL and ComboFix logs: