View Full Version : Win32:Sirefef-AAP Rtk

2012-06-30, 03:23
Greetings. I scanned my computer with AVAST! Anti-Virus and found several detections of rootkits and potential malware in my system. One example is the Win32:Sirefef-AAP [rtk]. I have tried quarantined these infections in "chests," but when my computer restarts and I run another scan, the infections reappear as if the scan did nothing to help. Can you please help me successfully remove these infections from my computer's system?

2012-07-02, 21:43
Welcome to Safer Networking. I am maxi, and I will be helping you out with your malware problems.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.

Please observe and follow these Forum Rules (http://forums.spybot.info/showthread.php?t=288).
Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
Please read the instructions carefully and follow them closely, in the order they are presented to you.
If you have any doubts or problems during the fix, please stop and ask.
All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
If you do not reply within 3 days, this topic will be closed.

If you are agreeable to the above, then everything should go smoothly

As I am currently still in training, everything that I post to you must be first checked by my teacher. This may add a tiny delay between replies so please be patient :)

Do you still require help ? If so could you please post the attach.txt. You may have to run DDS again to get this if you have not already saved it.

2012-07-02, 23:43
Hi, Maxi. I wasn't initially sure if I should've included it; therefore, I didn't post it. Fortunately, I had it saved on my desktop. Here it is...

2012-07-03, 18:04
Hi JohnShooter :)

The first thing you you need to do is update your Avast! virus definitions, Then you need to locate the detected files in the virus chest and rescan them. You can do this by right clicking on the detected file and selecting scan. If the files come back clean you can right click them again and this time select restore.

Please let me know if the files are still showing as infected and if so could you supply me with the files and paths of the infected files.

Step 1 (if you havn't already done so)
Back Up registry with ERUNT

Please download ERUNT (http://www.aumha.org/downloads/erunt-setup.exe) and save it to your desktop.
Alternate Download (http://dundats.mvps.org/Files/erunt-setup.exe)
Double-click on erunt_setup.exe to install the program
Untick the NTREGOPT desktop shortcut option
Click No when you get the option to run Erunt at Windows startup.
During the installation, tick Launch Erunt.
Accept the default options for running a backup.
Erunt will then backup your registry.
Click OK to finish.
If you are unable to back up your Registry with ERUNT ....

Let me know.
Do not follow any further instructions until I tell you to.

Step 2
Add/Remove programs
Click on start
Then Run
In the open text entry box please copy/paste appwiz.cpl Then click enter.
Press the "Remove" or "Change/Remove"...button to uninstall the following if present.

Java Auto Updater
Java(TM) 6 Update 29
YouTube Downloader Toolbar v5.9
YTD YouTube Downloader & Converter 3.7

You can download the latest version of Java from here (http://download.oracle.com/otn-pub/java/jdk/7u5-b05/jre-7u5-windows-i586.exe), Just download the file to your desktop and install the program.

Step 3

Please download TDSSKiller.exe (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
Double click on TDSSKiller.exe to launch it.
Click on Start Scan, the scan will run.
When the scan has finished, if it finds anything please click on the drop down arrow next to Cure and select Skip
Now click on Report to open the log file created by TDSSKiller in your root directory C:\
To find the log go to Start > Computer > C:
Post the contents of that log in your next reply please.

Step 4
Please download OTL (http://oldtimer.geekstogo.com/OTL.exe) by Old Timer and save it to your Desktop.

Double click on OTL.exe to run it.
Under Output, ensure that Standard Output is selected.
Under Extra Registry section, select Use SafeList.
Click the Scan All Users checkbox.
Click on Run Scan at the top left hand corner.
When done, two Notepad files will open.
OTL.txt <-- Will be opened
Extra.txt <-- Will be minimized
Please post the contents of these 2 Notepad files in your next reply.

In your next reply please include:
The results of the file rescan with Avast.
The TDSSKiller log.
Both logs from OTL.
Any problems you had with my instructions.
Any symptoms of Malware you are experiencing.

Regards maxi :)

2012-07-03, 22:09
After the Avast Scan, cercsyr6.sys was found not to have any virus, so I restored it. The I/I.class, on the other hand, resulted in being labeled as a Java:Malware-gen [Trj] after rescan. It's still quarantined in the chest.

Here are some of the symptoms:
- glitching in the audio whenever I listen to music on youtube or soundcloud.
- internet also invariably freezes whenever I go web surfing. There was also - popup that appears on my desktop which said about setting up/changing language settings.
- Another pop up tells me that adobe flash update has encountered an error, and that I should send an error report.

I've installed the most up-to-date version but the adobe flash error pop up still comes up from time to time. The symptoms aren't terribly serious, but they've made me awfully worried. Especially after running the AVAST scan and finding those infections that I previously mentioned in my first post.

I had a bit of trouble getting this post to you because, well, the computer keeps freezing. Do you know what may be causing the problem?

2012-07-03, 22:13
Having trouble getting the rest of the scans to you. The site is only allowing me to post once every 20 minutes. Also there's a character limit and the reports are REALLY long. Please bare with me.

2012-07-03, 22:14
14:38:34.0015 2528 ============================================================
14:38:34.0015 2528 Scan started
14:38:34.0015 2528 Mode: Manual;
14:38:34.0015 2528

2012-07-03, 22:15
14:38:43.0687 2356 Detected object count: 0
14:38:43.0687 2356 Actual detected object count: 0

2012-07-03, 22:19
OTL logfile created on: 7/3/2012 2:40:14 PM - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\JR\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 349.00 Mb Available Physical Memory | 34.45% Memory free
3.87 Gb Paging File | 3.32 Gb Available in Paging File | 85.69% Paging File free
Paging file location(s): C:\pagefile.sys 3048 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.47 Gb Total Space | 171.29 Gb Free Space | 74.64% Space Free | Partition Type: NTFS

Computer Name: OWNER-33EF7E690 | User Name: JR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

< End of report >

2012-07-03, 22:27
O1 HOSTS File: ([2012/06/26 00:21:02 | 000,442,103 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts

(I tried posting this before, but the rest is all gibberish written in either Japanese or Chinese. Do you still want me to post it? I've been having trouble doing so because it's excessively long.)

OTL Extras logfile created on: 7/3/2012 2:40:14 PM - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\JR\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.10 Mb Total Physical Memory | 349.00 Mb Available Physical Memory | 34.45% Memory free
3.87 Gb Paging File | 3.32 Gb Available in Paging File | 85.69% Paging File free
Paging file location(s): C:\pagefile.sys 3048 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.47 Gb Total Space | 171.29 Gb Free Space | 74.64% Space Free | Partition Type: NTFS

Computer Name: OWNER-33EF7E690 | User Name: JR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

2012-07-04, 19:12
Hi JohnShooter :)

I notice that you have Microsoft Office Enterprise 2007 installed. Could you tell me how this came to be on your machine ?

Step 1
Please download MGA Diagnostic Tool (http://go.microsoft.com/fwlink/?linkid=52012) and save it to your Desktop.

Double click on MGADiag.exe to run it.
Click Continue.
The program will run. It takes a while to finish the diagnosis, please be patient.
Once done, click on Copy.
Open Notepad and paste the contents in the window.
Save this file and copy/paste it in your next reply.

Step 2
Run CKScanner

Please download CKScanner from Here (http://downloads.malwareremoval.com/CKScanner.exe)
Important: - Save it to your desktop.
Double-click CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved. Please Run the program only once.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

In your next reply please include:
The answer to my question.
The CKScanner log.
The MGADiag log.
If you removed the programs I asked you to remove before or after running OTL.

Regards maxi :)

2012-07-06, 01:41
I installed Microsoft Office way back when I first got my computer--that must've been sometime back in '08 or '09 if I remember correctly. Is there any problem arising from its presence?

Apologies. I accidentally missed that part. Yes, I have now successfully uninstalled those specific programs.

OEM Activation 2.0 Data-->

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.IUNAXP
----- EOF -----

2012-07-06, 19:58
Hi Johnshooter,

The Microsoft Office Enterprise 2007 on your computer is a non-genuine copy. It was installed with a now blocked Volume Licensing Key (VLK) that was valid and only available to corporations, education entities and government agencies. VLKs are blocked by Microsoft at the request and consent of the original keyholder for such reasons as the key was lost, stolen, compromised, misused, or expired. Also, Microsoft may have blocked the key if it notices a pattern of misuse, that is more installations of XP using that key than authorized.
A VL Product Key is non-transferable to individuals.

Please read Illegal copies of software (http://forums.spybot.info/showpost.php? ... ostcount=4)
If you still want help, please remove the illegal items from your computer, and if you still need the softwares, get legal ones from legitimate sources.
If you advised that the illegal softwares have been removed and I find it otherwise (the tools we use can and will detect them), then I will have no choice but to have this topic closed.
If there are more such new findings after this, the topic will also be closed.

You may return to the seller to demand for a replacement with a genuine copy or get a full refund. Have a read here (http://www.microsoft.com/genuine/downloads/FAQ.aspx?displaylang=en#ID0EKNAC) to see if you qualify for Genuince Office Offer. As an alternative, you can also try OpenOffice (http://www.openoffice.org/).

If you still want help, remove Microsoft Office Enterprise 2007 and post a fresh MGADiag log.

Regards maxi

2012-07-10, 02:35
Due to lack of response, this topic is now closed.

If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. How to post a DDS log. (http://forums.spybot.info/showpost.php?p=1150&postcount=2)

If it has been less than three days since your last response and you need the thread re-opened, please send a private message (pm) to me or a MOD. A valid, working link to the closed topic is required. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

Everyone else please begin a New Topic.