Another Sirefef.xx

Discussion in 'Malware Help (A Specialist Will Reply)' started by Azrith, Jul 22, 2012.

  1. Azrith

    Azrith Private E-2

    OK so it's clear I've done something stupid enough to contract a nice one. Not sure what lead to it but reading stickies in here has been huge learning experience. I'm pretty convinced I need to clear this off with the FRST method after going through many of the sticky suggestions and older threads. I would love some help and you guy are obviously pro's at this. Would love to avoid a complete reinstall but that'll be my next step if I can't clean it.

    Anyways onto the problem. MSE is complaining about numerous Sirefefs every so often and I'm seeing redirects off Chrome searches (that was the first tip that something was wrong). I've tried all scans and fixes but it seems to come back. Sooo.. here is the FRST log. Hoping that I took the right direction.
     

    Attached Files:

  2. Azrith

    Azrith Private E-2

    Attaching the other logs as well in case those are needed.
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, Azrith :)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  4. Azrith

    Azrith Private E-2

    Heya thisisu - thanks for the help.

    Applied and attached.
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    Hi Azrith,

    The fixlog looks good. Let me know what malware issues remain.
     
  6. Azrith

    Azrith Private E-2

    Thisisu,

    None that I can tell so far, I wanted to give it a at least 24hrs to make sure nothing popped up. The largest evidence was Google search redirects and MSE getting angry about Sirefef,<insert 1-2 random alphas> along with numerous IP BLOCKS from MWB - NONE of these have occurred since cleaning.

    I've turned UAC back on but going to wait another day or two before toggling system restore.

    Anything else I need to do?

    Oh and again, you guys rock. The sticky posts are great and wonderful help from you all.
     
  7. thisisu

    thisisu Malware Consultant

    You can delete the C:\FRST folder at this time.
    No problem take your time.

    Here are the final instructions if everything turns out okay:

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds