Win64 Sirefef.B has beaten me, please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ToneyTime, Aug 6, 2012.

  1. ToneyTime

    ToneyTime Private E-2

    Hello, I have read many responses to this issue and was hoping I would be able to get some help with this issue.

    History:
    Originally I was seeing page redirects and Microsoft Security Essentials was giving me errors. I ran Avast pre-boot scan and cleaned, everything seemed fine. I checked MSE and it was still having the same issue, I reinstalled and now I am seeing it discovered Win64: Sirefef.B Virus. Since then, almost immediately after each boot I am getting a pop-up stating Windows will restart itself. I cannot stop the shutdown, no strange services to my knowledge, and this occurs in safe mode as well. System restore has not been able to help.

    Because of the short reboot window I have not been able to fix much - I have attached the Farbar results. Any help is greatly appreciated!!
     

    Attached Files:

    Last edited: Aug 6, 2012
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    You now need to follow these peocedures and attach all of the requested logs after doing so.

    READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  3. ToneyTime

    ToneyTime Private E-2

    Great, thank you so much it's booting up again! You saved me a lot, I am going to try to do it right- now realizing how much I would have had to do to start over. Do you have any opinions or suggestions?

    I'm currently running MalwareBytes (Clean Check) and Avast (Running) to do a quick check.
    Ran a new FRST (attached- or should I do it with another restart first?)

    Then I plan on:
    Clear System Restore Points, start a new one.
    Backup Docs/Media to external drive, then move to new partition.
    Create image iso.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the rest of the requested logs. :)

    From running:
    • MGTools.exe
    • Malware Bytes
    • HitmanPro
    • RogueKiller
     
  5. ToneyTime

    ToneyTime Private E-2

    Great, found some more of them
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are almost there. :-D I need the whole zipped file from you running MGTools.exe which is: MGlogs.zip.
     
  7. ToneyTime

    ToneyTime Private E-2

    Ah OK- Attached!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.
    TDSSkiller - How to run



    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    • Now re-run RogueKiller - no fix just a scan and attach the log.
    • Re-run FRST - no fix, just a scan and attach the log.
    • Let me know how things are running at this point.
     

    Attached Files:

  9. ToneyTime

    ToneyTime Private E-2

    Hey really, thank you so much for all of this help! I've attached the two logs - running RogueKiller now.
     

    Attached Files:

  10. ToneyTime

    ToneyTime Private E-2

    Ok, additional logs uploaded below. So far after some extended use - Everything is running amazingly!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    • Re-run FRST - no fix, just a scan and attach the log.
     

    Attached Files:

  12. ToneyTime

    ToneyTime Private E-2

    OK, attached.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry Toney, need to run it again correctly.
     
  14. ToneyTime

    ToneyTime Private E-2

    Sorry I haven't replied with the logs yet, currently in the process of moving but hopefully by Monday I should be set to finish this bug off!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Alright. I'll be floating about somewhere. ;)
     
  16. ToneyTime

    ToneyTime Private E-2

    Finally unpacked, setup! Last time I move in Florida, 3rd floor in August :cry

    Correct log uploaded!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download this file to your desktop. Now ensure anti virus is disabled.

    BITS.reg


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BITS.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. ToneyTime

    ToneyTime Private E-2

    You are crazy awesome! thanks again - posted log.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Still need to repair BFE and BITS but let's first see if we can get the firewall back up and running. ENSURE your antivirus is disabled please, it could hinder our fix.

    Download these two files to your desktop.

    MpsSvc.reg
    BFE.reg


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BFE.reg file saved to your Desktop and double click it. Allow it to be added to the registry. Repeat this for the MpsSvc.reg file.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. ToneyTime

    ToneyTime Private E-2

    Instructions followed, sensei please review attached.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello. :) Those logs look beautiful now. How's everything running?
     
  22. ToneyTime

    ToneyTime Private E-2

    Everything is running beautifully! Its amazing how many forum posts were about this and similar viruses out there - thank you SOOOO much for spending time and your skills helping me out! I had so many friends that told me format it and call it quits but I had so much to lose on it!

    How do you recommend I prepare for disaster?

    From Earlier, this is my plan, whats your take?
    Clear System Restore Points, start a new one now.
    Backup Docs/Media to external drive.
    I wasa told to put OS on own partition but dont know if there is an easier way to do this after the install other then moving all the other stuff over.
    Create image iso, backup on external.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am so glad!! :)

    Many of your questions will be answered by you following/reading the below final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds