The Technology Troubleshooting Thread

I have two really nasty viruses (no idea how I got them) and I can't get rid of them.
Trojan:
Win32/Sirefef.AB
Win32/Sirefef.P

There are many other variations of this virus but these two are the recurring ones.

I think I got this yesterday. I have Windows Security Essentials (Windows 7 Professional computer) and the virus scanner catches them and deletes them everytime but they comeback everytime I turn on my computer (the virus scanner requires a reboot to get rid of them so basically its a never ending cycle).

The viruses managed to turn off my firewall, the action center and my virus scanner. I have been able to turn the virus scanner back on but no luck with the Firewall or the action center. I have worked at getting rid of this virus all night but obviously I have had no luck.

Also from what I can tell this is a relatively new virus so maybe people havent found a way to get rid of it yet. One fix many people are saying is to do a clean install (or something like that) but I don't have a windows 7 dvd (which I think you need). My dad got this from a an out of buisness sale (Its a laptop which came with Windows 7).

I tried to get help from Microsoft but they want me to pay them 100 bucks just to see if they could fix it so screw them.

I don't know if this helps but the two viruses are located in C:\Windows\assembly\GAC_32\Desktop.ini
 
1. Did changing the DNS server work?

2. Additionally, do you have Adobe Creative Suite products on your machine? Do you know why all those adobe links would be there?

3. Did you do a full scan with MSE?

4. Have you tried accessing facebook through proxy?
After changing the DSN server, it seems to be working fine. But I'll have to keep an eye in case it doesn't connect later on. And no, a full scan didn't find anything wrong.
 
After changing the DSN server, it seems to be working fine. But I'll have to keep an eye in case it doesn't connect later on. And no, a full scan didn't find anything wrong.

After a while it stopped working. I've also tried other internet services to the same results. No response with the www.facebook.com link, but the 66.220.149.11 IP link is working for now.
 
I have two really nasty viruses (no idea how I got them) and I can't get rid of them.
Trojan:
Win32/Sirefef.AB
Win32/Sirefef.P

There are many other variations of this virus but these two are the recurring ones.

I think I got this yesterday. I have Windows Security Essentials (Windows 7 Professional computer) and the virus scanner catches them and deletes them everytime but they comeback everytime I turn on my computer (the virus scanner requires a reboot to get rid of them so basically its a never ending cycle).

The viruses managed to turn off my firewall, the action center and my virus scanner. I have been able to turn the virus scanner back on but no luck with the Firewall or the action center. I have worked at getting rid of this virus all night but obviously I have had no luck.

Also from what I can tell this is a relatively new virus so maybe people havent found a way to get rid of it yet. One fix many people are saying is to do a clean install (or something like that) but I don't have a windows 7 dvd (which I think you need). My dad got this from a an out of buisness sale (Its a laptop which came with Windows 7).

I tried to get help from Microsoft but they want me to pay them 100 bucks just to see if they could fix it so screw them.
That looks like a nasty little bugger.

Try downloading rkill/iExplore from the free tools thread I have in this forum. Put it on your desktop. Restart the computer and boot into Safe Mode (usually by pressing F8 when your computer first boots). Once into Safe Mode, run rkill/iExplore and see if it does anything. Then try running a full MSE scan again.

If that doesn't work, you'll need to search out the manual removal instructions.
After a while it stopped working. I've also tried other internet services to the same results. No response with the www.facebook.com link, but the 66.220.149.11 IP link is working for now.

You're not very good at answering all of my questions.

Do you have Adobe products besides flash player on your machine? Have you tried accessing it through a proxy?
 
That looks like a nasty little bugger.

Try downloading rkill/iExplore from the free tools thread I have in this forum. Put it on your desktop. Restart the computer and boot into Safe Mode (usually by pressing F8 when your computer first boots). Once into Safe Mode, run rkill/iExplore and see if it does anything. Then try running a full MSE scan again.

If that doesn't work, you'll need to search out the manual removal instructions.

Which safe mode should I use (there are 3 options for safe mode)?
 
Holy crap that program got rid of the last virus (I have used about 6 other programs which got rid of the first part). My firewall is back on and my action center is on as well thank you.
 
Had After Effect, have Photoshop and Bridge. And I don't know how to access via a proxy.

http://www.hidemyass.com/

Try that.

Holy crap that program got rid of the last virus (I have used about 6 other programs which got rid of the first part). My firewall is back on and my action center is on as well thank you.

That program stops it from running, and MSE should hopefully come behind and clean it up. And you want just regular safe mode, not command prompt or networking.
 

I can get the page, I can't log in though.

After adding # in front of every IP address except the Facebook ones, it seems to be working fine. However, every time I save MSE says a threat is detected but also says "no action required". I assume it's because I'm tampering with important files.

EDIT: And after a while, the links stopped working. This is starting to piss me the hell off.
 
I can get the page, I can't log in though.
You don't have to login. Just type in Facebook's address in the URL bar provided.

After adding # in front of every IP address except the Facebook ones, it seems to be working fine. However, every time I save MSE says a threat is detected but also says "no action required". I assume it's because I'm tampering with important files.
What are you talking about here? I'm confused. Are you talking about the hosts file?
 
You don't have to login. Just type in Facebook's address in the URL bar provided.
I did. It says I need to enable cookies.

What are you talking about here? I'm confused. Are you talking about the hosts file?
When I edit the host files and save, it works fine for a bit, but then goes right back to not connecting.
 
I did. It says I need to enable cookies.
Hmm...works fine for me.

When I edit the host files and save, it works fine for a bit, but then goes right back to not connecting.
Please answer this question for me. When you can access Facebook on your phone, is your phone using the same Internet source as your computer? Or are you connecting to Facebook using a data plan for your phone?
 
Hmm...works fine for me.

Please answer this question for me. When you can access Facebook on your phone, is your phone using the same Internet source as your computer? Or are you connecting to Facebook using a data plan for your phone?

The phone has it's own data plan. It's Sprint. However, come to think of it, even though when on the computer I've used multiple internet connection's and are technically different sources (one is a USB card the others were broadband) they have so far been the same provider.

I managed to log in via Hide My Ass. The result was kinda odd:

2cys68h.jpg


Also, after rebooting the computer, the changes I made to the hosts file were gone.
 
The phone has it's own data plan. It's Sprint. However, come to think of it, even though when on the computer I've used multiple internet connection's and are technically different sources (one is a USB card the others were broadband) they have so far been the same provider.

Hmm, I'm guessing the problem is your machine. Try this link.

http://support.microsoft.com/kb/972034

And then boot into Safe Mode and run a virus scanner. It really does sound like you have some kind of malware on there hijacking your browser.
 
Reset the host files and full scanned the PC on safe mode. After a restart and retrying... Nothing.
 
Is your PC Firewall on? Do you have a wireless router?

I found the solution. Now that I think about it, it should've been the first thing to do. Seems an update on Windows' part blocked me out. I ran a second full scan afterwards just in case to clean results. System Restore.
 
Good to hear.

Sorry to bother, had the same problem. Again. However, this time I was able to get a different, but still being tested solution. I was suggested that Windows' installed web filter may be a problem as it might block Facebook due to some features. So I went to it and added Facebook as "https://www.facebook.com" to it's list of Safe websites. It's worked perfectly since but given how every time I "fixed" it, be it changing the IP address, DNS, System Restore and such after a while it may just go right back to not connecting. My question is if it's really possible that the web filter may block certain pages like that.

[EDIT] Nevermind, it went right back to being unresponsive.
 
How does one delete a false movie file from one's system directory?

I downloaded a movie file that turned out to be a decoy movie file (created by a grubby little cockroach building malicious computer software in his parents' basement while boning his pet dog because the family cat rejected this sad sad person's advances; you know who you are, get a real job you disturbed little freak!).

Now I cannot delete the file because Windows, in all of its "robot with advanced autism" wisdom, has decided that the file "is being used by another person or program."

Can anyone please tell me how to avert this crisis before I start slamming my laptop against the wall?
 
Sorry to bother, had the same problem. Again. However, this time I was able to get a different, but still being tested solution. I was suggested that Windows' installed web filter may be a problem as it might block Facebook due to some features. So I went to it and added Facebook as "https://www.facebook.com" to it's list of Safe websites. It's worked perfectly since but given how every time I "fixed" it, be it changing the IP address, DNS, System Restore and such after a while it may just go right back to not connecting. My question is if it's really possible that the web filter may block certain pages like that.

[EDIT] Nevermind, it went right back to being unresponsive.
How serious are you about wanting to figuring out this problem? How much RAM and hard drive space does your computer have?

How does one delete a false movie file from one's system directory?

I downloaded a movie file that turned out to be a decoy movie file (created by a grubby little cockroach building malicious computer software in his parents' basement while boning his pet dog because the family cat rejected this sad sad person's advances; you know who you are, get a real job you disturbed little freak!).
I'm going to assume you were trying to download a movie illegally, which makes it humorous that you are criticizing another person's integrity. :)

Now I cannot delete the file because Windows, in all of its "robot with advanced autism" wisdom, has decided that the file "is being used by another person or program."

Can anyone please tell me how to avert this crisis before I start slamming my laptop against the wall?
It depends...is this a virus file? If it is, you run Microsoft Security Essentials. If it's not, you plug your laptop in, reboot into Safe Mode (usually by pressing F8 when you first turn your laptop on, before it boots into Windows) and try deleting it that way. If that doesn't work, try the program Unlocker.
 
Is there any way I can record the desktop playback (A video version of PrintScreen)? I downloaded a program called CamStudio but the video size is very high (about 500MB for a 5 min video).
 

Users who are viewing this thread

Members online

No members online now.

Forum statistics

Threads
174,826
Messages
3,300,732
Members
21,726
Latest member
chrisxenforo
Back
Top