Author Topic: System 32 infected with Win32:Sirefef-ZT [Trj]  (Read 5956 times)

0 Members and 1 Guest are viewing this topic.

Jindy

  • Guest
System 32 infected with Win32:Sirefef-ZT [Trj]
« on: July 22, 2013, 03:54:42 PM »
If anybody could help I would really appreciate it.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #1 on: July 22, 2013, 03:56:44 PM »
Please attach your logs. (AdwCleaner, MBAM, OTL and aswMBR..!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #2 on: July 22, 2013, 03:57:39 PM »
Monitoring

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #3 on: July 22, 2013, 03:59:44 PM »
I can't access any web pages, (using google chrome) comes up with the security certificate has been revoked. Currently using an iPad to access this forum

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #4 on: July 22, 2013, 04:01:00 PM »
Are you able to access them with IE ?  If not I will give you links to the programmes I hold in my dropbox

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #5 on: July 22, 2013, 04:05:16 PM »
Am able to access, will post logs momentarily

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #6 on: July 23, 2013, 03:03:17 AM »
logs

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #7 on: July 23, 2013, 03:04:03 AM »
and the extras one for OTL

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #8 on: July 23, 2013, 03:54:24 PM »
OK killing time :)

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

THEN

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2138707725-3357649288-2608841478-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
[2013/07/23 00:27:11 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2013/07/23 00:27:11 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini

:Files
C:\WINDOWS\Installer\{f036bac4-b1a8-d067-d737-8fd048ab7bbf}
netsh advfirewall reset /c
netsh int ip reset c:\resetlog.txt /c
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #9 on: July 25, 2013, 09:56:02 AM »
sorry essexboy, been really busy, i will try this tonight and post the results. thanks for your help

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #10 on: July 25, 2013, 03:16:45 PM »
Combo fix has been seemingly stuck on "output folder: C\32788r22fwjfw" for over an hour now
Any help please?



Edit, fixed. Worked after and hour and half, phew
« Last Edit: July 25, 2013, 03:27:59 PM by Jindy »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #11 on: July 25, 2013, 03:49:52 PM »
Sometimes combofix has a problem with an infection and needs to beat it to death :)

le potier

  • Guest
Bonjour,

Je voudrais installer ma licence "AVAST INTERNET SECURITY", 3 PC sur le PC portable de ma fille.

Comment dois-je faire ?

Merci pour les conseils que vous pourrez me donner .


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #13 on: July 25, 2013, 05:54:03 PM »
le potier, allez sur cette lien http://forum.avast.com/index.php?board=23.0 et cree une nouveau discussion sur votre probleme.

Merci,

Michael

(Je suis desole pour aucune Accents, j'ai utilise une claiver Francais)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Jindy

  • Guest
Re: System 32 infected with Win32:Sirefef-ZT [Trj]
« Reply #14 on: July 26, 2013, 02:46:03 PM »
Ok, so I ran combo fix, then when the computer rebooted and it made the log, I tried the program's, and they were marked for deletion. As the instructions said, I rebooted the computer, when I rebooted it, windows updated 34 different things ( through windows update ) now that my computer is starting again it tried to apply the updates, failed, and now it's reverting the changes. Is this normal? Or should I have turned my Internet off when using combo fix.....