Sirefef Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nhmn, Oct 11, 2012.

  1. nhmn

    nhmn Private E-2

    Hello everyone,

    To get right to the heart of the situation I am posting here in seek of professional assistance in removing the Sirefef virus from my PC as it appears this one is far beyond my capabilities and that I would also need help with a unique fixlist. I noticed many individuals were receiving excellent assistance here and the tools required are ones that I have no experience with so I must unfortunately get in line. I'm a bit overwhelmed so I will try to break this down a bit...


    Symptoms/Culprits/Information
    I am at a bit of a disadvantage because I have absolutely no clue when I contracted the virus simply because there were no obvious symptoms. My PC was not running slow nor having any abnormal reactions. The only out of the ordinary occurance was a strange windows error I had never seen before popping up once two days before my finding this issue and once the day before.

    I was doing a normal restart and upon checking the task manager I saw something by the name of "beacucqitear.exe" running, it had not been present before the restart or any time prior to that. Without thinking much of it I deleted it from my system manually, after googling it I tried to check on windows defender and found it not working. I downloaded Microsoft Safety Scanner to do a quick scan and it found both Sirefef.B and Sirefef.Y. It "removed" them and upon its completion I ran a full scan and it gathered up many more hits including Sirefef!cfg, P, AB, M, W.

    • I am using Windows 7 64-bit Home Premium.

    Questions
    • I am completely confused as to how this made it onto my system, for both peace of mind and future reference how exactly does one contract this nasty virus?
    • With all of these variants present would I be better off nuking windows and reinstalling? I have the option but would prefer not to choose it unless there is no other choice.
    • How far can the infection spread and what files might be in danger? Will this spread to more recreational files or will it only spread through system files?

    FRST

    Ive read through all of the other threads working through this issue and went ahead and walked through the first step with the Farbar Recovery Scan Tool. Below is my FRST.txt



    A huge thank you in advance for any help you can provide and for the insight located throughout the forums and website.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.
    Running MGTools.
     

    Attached Files:

  3. nhmn

    nhmn Private E-2

    Hello and thanks for the response.

    Below is my fixlog, I will run MGtools now and report back.
     

    Attached Files:

  4. nhmn

    nhmn Private E-2

    Sorry for the wait, here is my MGtools report.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    You also need to run CCLeaner and clean out your temp folders.

    You should not have BItTorrent running at start up. It opens your system to everyone.

    Otherwise, your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  6. nhmn

    nhmn Private E-2

    Thank you immensely for your help, sorry for the jumbled mess.


    Everything looks like its back to normal now and it seems to be running great again, the only lingering issue is that windows firewall and defender will not run, are missing, and resist when I try to reinstall.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds