Author Topic: need some help with removing trojan win64\sirefef.y  (Read 37341 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #15 on: June 18, 2012, 10:08:48 PM »
Darn and no USB drive either ?

Could you burn the windows 7 recovery console and FRST to the same disc ?
Then burn the FRST log once produced - Without the log I cannot see where to resolve the problem

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #16 on: June 18, 2012, 10:13:37 PM »
will try to burn win7 rc and frst64 to another disc, but the link for win7rc points to the 32-bit one.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #17 on: June 18, 2012, 10:14:51 PM »
There are two links - one 32bit and one 64

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #18 on: June 18, 2012, 10:17:21 PM »
both point to the 32-bit one, but I found it.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #19 on: June 18, 2012, 10:17:47 PM »
Duh colour me stupid  :-[

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #20 on: June 18, 2012, 10:21:10 PM »
so after it's done downloading, I burn this iso image and frst64 to the CD, then run this instead of that Reatogo environment? then after the scan there, how do I burn that txt result file back to CD from the RC?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #21 on: June 18, 2012, 10:25:21 PM »
From the RC you should be able to copy it to the CD ... I will check to see if there are additional commands required..


One other thing to try is to use the CD and select startup repair initially to see if that can get us part way in

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #22 on: June 18, 2012, 10:27:15 PM »
just to let you know, it does boot into windows, but after everything is loaded up, then a popup appears that says critical error, will restart in 1 min, would a repair still be needed?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #23 on: June 18, 2012, 10:32:54 PM »
Can you get to safe mode ?  I was under the impression it was looping

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #24 on: June 18, 2012, 10:34:54 PM »
I can get to safe mode, but it does the same thing with that popup that then reboots the pc after 1 min, so I can't really do any scanning from within Windows.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #25 on: June 18, 2012, 10:36:27 PM »
Try a startup repair then - Is the warning NT access perchance or just critical error

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #26 on: June 18, 2012, 10:37:53 PM »
Also within that minute have you tried shutdown /a from an elevated command prompt ?

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #27 on: June 18, 2012, 10:49:35 PM »
critical error, but it doesn't look like a standard Windows error, but it using the aero theme though. it says to save any work and stuff like that, when the current av (MSE) tries to automatically remove it.

haven't tried that. after shutdown /a it still reboots.

cool_gecko

  • Guest
Re: need some help with removing trojan win64\sirefef.y
« Reply #28 on: June 18, 2012, 10:53:37 PM »
without logging into Windows, it reboots itself with no error message.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: need some help with removing trojan win64\sirefef.y
« Reply #29 on: June 18, 2012, 10:54:26 PM »
Is there any way you can disable MSE before it removes it, or tell it to ignore it ?