Recommended Posts

I've never heard of Malwarebytes NOT removing something in the FREE version. I haven't used in several months, though, so I can't say for sure.

Here are some free bootable AV CDs:

http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/

You also might try http://en.kioskea.net/faq/13346-windows-delete-the-files-in-c-recycle-bin

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595424954
Share on other sites

I also checked with Maleware Bytes scan....got 3 objects detected .....but FREE version does not have removal facility .

False, your virus looks like it is in a protected system folder which the AV software does not have permissions to. Not really sure why you assume that the free version doesn't remove infections, because it does. You need to look into taking ownership of the Recycle Bin folder

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595424958
Share on other sites

where is the remove feature here ? This is the scan result of Maleware Bytes.

How do I remove detected objects ?

bytes_zps3d57270c.png

>>>>Yeah Id say that, Empty Recycle Bin.

Recycle Bin is already empty !....restarted machine ...no improvmenet.

Probably in Show Results.

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595425068
Share on other sites

I still wish Malwarebytes would take the superantispyware approch and show us what it finds as it finds it. Nothing is more annoying than when you do a scan on someones machine and it finds 1 infection in memory but you don't get to know what that infection is until 1 hour after the scan is complete. Only to find out it's mywebsearch.

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595425088
Share on other sites

I still wish Malwarebytes would take the superantispyware approch and show us what it finds as it finds it. Nothing is more annoying than when you do a scan on someones machine and it finds 1 infection in memory but you don't get to know what that infection is until 1 hour after the scan is complete. Only the find out it's mywebsearch.

Yep, I hate that too, makes me want to hit stop to see what it was, but then I cba to wait for another scan in-case it finds something at the end

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595425118
Share on other sites

Ok from what I read it is a new Trojan (Some people just have too much time on their hands) discovered in mid December, which is why malwarebyes can't remove it because it does not know how

Sirefef, or ZeroAccess, is a Trojan that infects machines by exploiting a browser, through a third-party plugin, via an email attachment/link or it?s downloaded by other malicious software (malware). Once on the machine, it creates an environment where new threats can be installed without detection by most security software and then downloads these threats. Because it prevents antivirus software attempting to remove it, Sirefef is very difficult to remove, often requiring a complete system reinstall.

http://land.viprebusiness.com/sirefef/?adv=2005&loc=1067&gclid=CPnhwZqYxbQCFQSg4Aod4iIAWQ

this may help

http://blog.teesupport.com/how-to-remove-trsirefef-bp-1-malware-manual-removal-of-trsirefef-bp-1-virus/

but if the system is compromised already i would reload from a clean backup but that's just my humble opinion because I have found many a time a lot of these 'removal tips or tools' are more trouble than they are worth...good luck

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595425162
Share on other sites

Iv`e just cleaned a lappie with this on using boot cd`s. Look like you were actually pretty lucky as it normally locks you out of the computer (ransomware). You have been caught blah blah blah, send some money via wire transfer and you can your computer back sort of thing :pinch:

Start sandboxing your browser...

Link to comment
https://www.neowin.net/forum/topic/1128510-virus-alert/#findComment-595426316
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Hello, Christian Maas' XVI32 is a nice (and very small) hex editor. Speaking of hex editors, many years ago a colleague and I who both worked at Tribal Voice managed to edit a copy of the company's PowWow instant messaging client to make it behave better now that all of its lookup servers and other server-side tech was gone.  The program didn't support NAT (RFC-3022 was introduced in January 2001, the same time Tribal Voice was shuttered), but it still worked okay if you manually set up port-forwarding on your router.  The server at http://powwow.jazy.net/ hosts a copy (usual warnings about downloading and running untrusted code from random internet servers apply). I occasionally use some tools like Funduc Software's Search and Replace and Application Mover when I need to make mass-edits to text-based files or move programs with a hard-coded installation directories, respectively.  When I need to figure out the exact LCD panel inside of a laptop, EnTech Taiwan's Monitor Asset Manager is my go-to tool for that purpose. JD Design's website (now hosted on github.io) has a number of interesting freeware and shareware utilities.  I used to use their TouchPro utility to set the file timestamps on software I was mastering to match its version number (e.g., version 3.00 of a program had all of its files dates set to 3:00AM, and so forth). Karenware has a number of interesting freeware utilities, too. Regards, Aryeh Goretsky  
    • I still use HexChat! Not really as ancient as the 1994 AutoCAD above my post, but I have never found anything better to replace it. Yes we still operate an IRC server https://www.neowin.net/irc/ 😛 
    • At work we still have a couple of people that use a version of AutoCAD LT purchased in 1994. This predates Windows 95 and works fine on versions of Windows up to XP. Its long since run in an locked down isolated XP VM, accessible via RDP. I did install LibreCAD for them, however they said it was just too different to get to grips with. In all fairness one of them is now 75 and the other is almost 60.
    • On my music making (non internet) PC Sony Acid Pro 7.0 Adobe Audition 2015 Korg Legacy Collection Windows 7 SP1
    • Anyway to download these versions without being on the Experimental builds?
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      82
  • Tell a friend

    Love Neowin? Tell a friend!