Sirefef.Y and Sirefefe.B :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by JoshyT, Aug 9, 2012.

  1. JoshyT

    JoshyT Private E-2

    hi there,

    I'm new here, but it looks like a good place to get help and learn how to help others. my computer recently contracted a virus, i had Norton on the machine but it didn't do anything to stop it, so i removed Norton and put on Microsoft Security Essentials, now the machine is detecting both Trojan:Win64/Sirefef.Y and Virus:Win64/Sirefef.B. My system restores wont work, its giving me an error message that says i have anti-virus software running and fails to restore. I'm at my wits end with this thing, so much work to do on it and i cant get it to stay on, as soon as it loads windows it says that a critical error has been found and windows will reboot in 1 minute, so i cant even do anything to try and remove this too.

    Please, if anyone has any suggestions, throw me a bone :)

    Josh.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have Win 7 or Vista...? If so...

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. JoshyT

    JoshyT Private E-2

    hi, here is the file you requested.

    thanks again.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Now follow these procedures. There is still an infected services.exe to take care of.

    READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  5. JoshyT

    JoshyT Private E-2

    thanks for your help so far. ive done as you have asked, but it still wants to restart the comptuer after 1 minute after i applyed the fix :(
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes because no doubt the services.exe is still infected so click on the blue link in my last post (Read and Run me First) and continue to work your way through those procedures and attach the rest of the requested logs. I could have you use FRST to find a suitable replacement for it however it's more thorough that you run all that I asked.
     
  7. JoshyT

    JoshyT Private E-2

    unfortunately, the machine wont stay logged on long enough for me to follow any of your extra instructions :( is there somthing i can do to keep it from shutting down so i can follow them?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (See: How to attach)
     
  9. JoshyT

    JoshyT Private E-2

    Here is the requested file. Thanks again for all your help.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Now run FRST again (no fix just a scan like you did the first time) attach log. See if you can now follow these procedures. READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds