Woody
Woody UltimaDork
3/31/12 5:35 p.m.

I crack myself up!

Seriously, one of my older computers is infected with a trojan. It appears to be Win32/Sirefef.AC

It uses Windows XP and Firefox if that matters. I am nearly computer illiterate so any help would be appreciated.

Thanks.

MG Bryan
MG Bryan Dork
3/31/12 5:47 p.m.

Have you run Malwarebytes?

BBsGarage
BBsGarage HalfDork
3/31/12 5:53 p.m.

?????????????????????

Toyman01
Toyman01 UberDork
3/31/12 5:59 p.m.
MG Bryan wrote: Have you run Malwarebytes?

This.

Woody
Woody UltimaDork
3/31/12 6:03 p.m.

I forgot about them. I'll give it a try.

Woody
Woody UltimaDork
3/31/12 6:15 p.m.

I can't even open Firefox or Internet explorer

novaderrik
novaderrik SuperDork
3/31/12 6:39 p.m.

if you have a reinstall disc, then maybe it's time for a reformat/reinstall..

ultraclyde
ultraclyde Dork
3/31/12 7:00 p.m.

I've had a couple that disabled the browser as well. If you can download Malwarebytes on another computer, use a flashdrive to get it onto the affected unit. Just MAKE SURE to scan the flashdrive with any and all antivirus software before plugging it into any nonaffected PCs. Flashdrives are the dirty needles of the computer world when you're talking viruses.

You may also be able to download firefox to a USB flashdrive and run it from the flashdrive, but it may block that as well.

MG Bryan
MG Bryan Dork
3/31/12 7:13 p.m.

Safe mode with networking?

Woody
Woody UltimaDork
3/31/12 8:17 p.m.

I scanned with Microsoft security essentials and it indicated that it removed the Trojan.

I can navigate normally here.

If I google Malwarebytes and try to click on the Cnet link, I get redirected to advertising. I've used Cnet before.

poopshovel
poopshovel PowerDork
3/31/12 8:35 p.m.

Have you tried flicking the tip to make the swelling go down?

neon4891
neon4891 PowerDork
3/31/12 10:00 p.m.
BBsGarage wrote: ?????????????????????

I would include the instruction pictures, but those are NSFW

N Sperlo
N Sperlo UltraDork
3/31/12 10:28 p.m.
neon4891 wrote:
BBsGarage wrote: ?????????????????????
I would include the instruction pictures, but those are NSFW

Grab at the base and roll upward.

Woody
Woody UltimaDork
4/1/12 6:08 a.m.

I downloaded Maywarebytes to a thumbdrive through a clean computer, but I cant get it to scan on the infected one. I immediately get Run Time Error 13 Type Mismatch.

Help!

Toyman01
Toyman01 UberDork
4/1/12 7:12 a.m.

Shut it down and start it in safe mode. That will load windows, but nothing else. On an XP computer if you shut it off while it's loading windows it will ask you if you want to run safe mode the next time you turn it on.

Woody
Woody UltimaDork
4/1/12 7:46 a.m.
Toyman01 wrote: Shut it down and start it in safe mode. That will load windows, but nothing else. On an XP computer if you shut it off while it's loading windows it will ask you if you want to run safe mode the next time you turn it on.

So are you saying turn it on and while everything is opening up, turn it off? I don't think I've ever seen safe mode listed anywhere (not that I've looked). Is that the only way to get into safe mode?

Toyman01
Toyman01 UberDork
4/1/12 8:03 a.m.

Yes, turn it on. When the loading windows screen comes up, turn it off. The next time you turn it on a DOS looking screen will come up saying it detected an aborted boot. It will ask if you want to start in normal mode, safe mode, and safe mode with the network. Start it in safe mode. The screen will look strange, it doesn't load anything other than the basic windows program. Any viruses won't have a chance to load. Then run Malwarebytes.

This is the only way I know to get it into safe mode. There are probably others, but I don't know them.

I had to do this to my netbook the last time it got corrupted. It's a bit of a PITA, but it worked.

Jay
Jay SuperDork
4/1/12 8:14 a.m.

Just hold down F8 while it's booting and you can get the safe mode menu. No need for any off/on trickery. (Specifically, press it just after the bios splash screen when it comes up with the "Starting MS Windows" text and the grey-on-black loading bar.)

Grtechguy
Grtechguy PowerDork
4/1/12 9:41 a.m.

I use "Combofix" from Bleeping computer with GREAT results.

EastCoastMojo
EastCoastMojo UberDork
4/1/12 9:55 a.m.

Good luck Woody, I hope you get it off of there!

szeis4cookie
szeis4cookie Reader
4/1/12 10:31 a.m.

Also, I would disconnect the machine from the Internet while you do the scan.

akamcfly
akamcfly HalfDork
4/1/12 12:45 p.m.

Get Ubuntu Linux and a vasectomy.

No more trojans of any kind.

corytate
corytate Dork
4/1/12 1:52 p.m.
akamcfly wrote: Get Ubuntu Linux and a vasectomy. No more trojans of any kind.

You'll need to log in to post.

Our Preferred Partners
sVPwltdybYDdFrMnyoQEtldY2P3PMzVCmum1eXpeqUEXo8En6FmXNpKh69Trcb6o