Author Topic: Win32:Sirefef-BMH  (Read 3019 times)

0 Members and 1 Guest are viewing this topic.

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Win32:Sirefef-BMH
« on: October 12, 2013, 12:59:08 PM »
A couple of days ago I downloaded and installed an app. After that, avast instantly detected an exe file as Win32:Sirefef-BMH and deleted it. So i got a little paranoid and downloaded malwarebytes and performer full scans with it, and also with avast run on startup. Zero detections. Is there a way to be sure i'm not infected anymore?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:Sirefef-BMH
« Reply #1 on: October 12, 2013, 01:09:31 PM »
Please follow the instructions as listed: http://forum.avast.com/index.php?topic=53253.0

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: Win32:Sirefef-BMH
« Reply #2 on: October 12, 2013, 01:22:57 PM »
As I said, 0 detections with malwarebytes. And there are the other logs.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Win32:Sirefef-BMH
« Reply #3 on: October 12, 2013, 01:49:48 PM »
I'll notify essex.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Sirefef-BMH
« Reply #4 on: October 12, 2013, 02:24:06 PM »
Looks like Avast killed it stone dead :)

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=hp&installDate=31/08/2013
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-1915086392-106916708-128322944-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=ES&userid=408f8b70-fd73-9426-422d-cbe5ee30225e&searchtype=ds&q={searchTerms}&installDate=31/08/2013
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: Win32:Sirefef-BMH
« Reply #5 on: October 12, 2013, 02:38:05 PM »
It's a relief to know avast killed it. Many thanks to all of you for your fast and helpfull attention. There are the logs for the quick scan.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Sirefef-BMH
« Reply #6 on: October 12, 2013, 02:41:46 PM »
Looking good, any problems ?

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: Win32:Sirefef-BMH
« Reply #7 on: October 12, 2013, 02:46:11 PM »
No problems or sympthoms at the moment

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Sirefef-BMH
« Reply #8 on: October 12, 2013, 02:49:13 PM »
Avast seems to be getting ontop of stopping them before thay can even install..  Prevention is best

If you are happy run Adwcleanr and click uninstall
Run OTL and click cleanup

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: Win32:Sirefef-BMH
« Reply #9 on: October 12, 2013, 03:08:39 PM »
Done