Sirefef.R & Sirefef.AH - roboots after 1 minute

Discussion in 'Malware Help (A Specialist Will Reply)' started by KenB2014, Jul 5, 2012.

  1. KenB2014

    KenB2014 Private First Class

    Last night, I noticed MSE was not running and I could not update or run a scan. I uninstalled and reinstalled MSE. It scanned and detected Sirefef.R and Sirefef.AH and a message appeared that the computer would shutdown in one minute. The same thing happens in safe mode.

    I am unable to run READ AND RUN ME FIRST because of the shutdowns (sending this from another computer).

    I ran FRST.exe and have attached the file.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below as we need to locate a backup file to replace an infected one.

    Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (See How to attach)
     
  3. KenB2014

    KenB2014 Private First Class

    Thank you.
    Here's the search results.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and tell me how things are working.
     
  5. KenB2014

    KenB2014 Private First Class

    I ran fix and attached the log.
    Windows started normally and did not do the 1 minute shutdown.

    I started MSE and tried to update the signatures, but it would not update.
    I checked to see if Windows Update was running in services.msc and it is not listed. I tried starting Windows Update and it said it could not check for updates, because the service is not running. I restarted the computer and no change.

    I ran Microsoft Fix-it and it found the Windows Update issue. It said it could not repair it, but it did appear to fix it and be running ok.

    MSE would still not update, so I uninstalled and reinstalled MSE. It updated and ran normally.

    Windows Firewall with Advanced Security snap-in failed to load.
    I ran Microsoft fix-it and it said it repaired the firewall, but it still won't start.

    Windows Security Center Service is turned off (can't be started)

    I haven't discovered any other problems so far.
    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run MGtools per the instructions in the below link and then attach the C:\MGlogs.zip file that it creates. Make sure all protection software is disabled and also that UAC is disabled before trying to run MGtools.

    Using MGtools
     
  7. KenB2014

    KenB2014 Private First Class

    I followed the instructions and MGTools completed. It did not create MGlogs.zip, but did create the individual .txt files in the MGTools folder. I searched the computer and the file doesn't exist. I zipped those files into the attached .zip

    Hope this file will work for you.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Things are looking pretty good other than your Windows Firewall not running. Let's take a shot at fixing it.

    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  9. KenB2014

    KenB2014 Private First Class

    Outstanding!
    Windows Firewall is fixed and it seems to be running well.

    I did have to uninstall and reinstall MSE again after the repair. It would not complete a check for updates, but does after the reinstall.

    MGtools logs are attached.
    Thanks
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have one more fix to do.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. KenB2014

    KenB2014 Private First Class

    Successfully added to the registry.

    Computer seems to be running well.
    Logs are attached.
     

    Attached Files:

  12. KenB2014

    KenB2014 Private First Class

    Just notice an issue since the malware.
    The desktop icons are auto arranging even when auto arrange is not selected. I position icons where desired, but they will re-position by name when refreshed or rebooted.

    Google searched and tried suggestions found on various sites, but it doesn't change.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay. Have not been able to be hear for a few days.

    There is not too much I can suggest for this other than creating a new user account and see if it works okay. This is typically a sign of corruption within the user account's registry hive. It has happened to many people Also some versions of Windows (like XP and 2K ) were notorious for just having issues like this which is why quite a few tools were written to save icon positions and restore them. The problem is that many times, all it takes is any refresh of the Desktop ( which happens frequently ) and they are moved again.

    You may want to check out the below:

    http://answers.microsoft.com/en-us/windows/forum/windows_7-desktop/everytime-i-refresh-my-desktop-the-icons-auto/f6ce434c-be50-496f-a07d-14f72bc16fb5?msgId=18f45e39-4118-459f-baa2-7130941ee02a

    Your logs are clean time for final cleanup below. But you may want to delay the clearing of restore points in step 9 ( that is if you still have any), just in case you want to try a system restore to see if it can help with the auto arrange of icons issue. I don't think it would help, but you never know. On the downside, it could also restore malware. :(


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. KenB2014

    KenB2014 Private First Class

    I did install a save/restore utility and have been using that, but it is a pain. I will work through the suggestions on the link and see if it may be a corrupt user account.

    I wonder if a repair install would correct this if nothing else fixes it.
    Any thoughts on the impact of doing a repair?

    I'll work through the final cleanup steps and I'll report back if I discover what is causing the icon issue.

    Thanks for all the help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't expect that it would fix the problem, but I cannot be positive of that. It's possible you may cause yourself other grief too. Perhaps you could look for ideas in the Software Forum.
     
  16. KenB2014

    KenB2014 Private First Class

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Hmmmm! Please let us know if you find a solution. I just got another thread that has the same problem after malware was remove. Thus far we have only see two such cases ( yours and the other users ).
     
  18. KenB2014

    KenB2014 Private First Class

    I resolved these problems. In addition to the icon desktop issue, Windows Update stopped working again.

    I did a repair (upgrade) install of Windows 7 and all updates, and all function has returned to normal. The icons even returned to their original layout before they started auto aligning. The original file must have existed, but was not being accessed for the desktop once the install was corrupted.

    It was painless to do the repair and may be the only fix...I haven't seen anyone on any forum successful with attempts short of this.

    Thanks for the help you all give us and I hope this helps others resolve this issue.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I had not found any sure fire way to fix this either. I did not think that even a system restore would work. Glad to hear a repair worked. Thanks for letting us know.

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds