Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.

Windows 7: Trojan win64/ sirefef.b and .J

24 Jan 2012   #1

Win 7 64bit Ultimate
Trojan win64/ sirefef.b and .J

Dell laptop has sirefef.b trojan sirefef.j trojan and win32/alureon.TK

These are all trojans.

The laptop has MicSecEssentials, and malwarebytes free version, both of which I put onto the computer after the viruses were there.

system Specs:
Dell Inspiron
intel i3 2130 2.3 ghz
4gb ddr3 ram
hd graphics 3000
Win 7 64

I wanted professional help to deal with these problems and I do not trust many random websites. Please assist! Any help will be greatly appreciated.


My System SpecsSystem Spec

24 Jan 2012   #2

Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer

My System SpecsSystem Spec
24 Jan 2012   #3

Win 7 64bit Ultimate

I was reading that one of these trojans will edit registry files and that the removal of the virus is complicated until these registry files are fixed.

Is this true? If so, what tool should I use.

Also, the Microsoft security essentials keeps detecting the threats and "successfully" removing them, but then it re-detects them 5 minutes later. What can I do to change this? Will the program that you linked me to be more effective at removing these viruses?

Sorry about all the questions, Please advise

My System SpecsSystem Spec

24 Jan 2012   #4

Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer

You can boot off AVG's CD

Rescue CD | PC Rescue and Repair Toolkit | AVG Worldwide

This should help...
My System SpecsSystem Spec
24 Jan 2012   #5

Win 7 64bit Ultimate

Also I ran the scan tool from microsoft and it did not find anything in quick scan??? yet MSE still reports these trojans??
My System SpecsSystem Spec
24 Jan 2012   #6

Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer

For what it's worth, I read in a post Kapersky was the only one to remove win32/alureon.T. Again, your mileage may vary. Also, remember not to keep two virus scanners on one system.
My System SpecsSystem Spec
24 Jan 2012   #7

Win 7 64bit Ultimate

upon removal of the sirefef.b trojan sirefef.j trojans the computer would not even boot into windows.

I really need some way to fix the registry before removing the virus, as the removal of the virus destroys the files and subsequently does not allow windows boot.

Anyhow, that is what I believe is going on
My System SpecsSystem Spec
24 Jan 2012   #8

Windows 7 & Windows Vista Ultimate

Hi, Beast52702.

What is going on is, based on the findings of MSE, it appears your computer is infected with a rootkit known as ZeroAccess.

ZeroAccess (Max++) Rootkit (aka: Sirefef) is a sophisticated rootkit that uses advanced technology to hide its presence in a system and can infect both x86 and x64 platforms. ZeroAccess is similar to the TDSS rootkit but has more self-protection mechanisms that can be used to disable anti-virus software resulting in "Access Denied" messages whenever you run a security application. For more specific information about this infection, please refer to:
This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.

If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable. It would also be wise to contact those same financial institutions to appraise them of your situation.

I suggest you take a look at the following link: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?. If you wish to format, there are very helpful tutorials here at Seven Forums on how to proceed.

Should you wish to attempt cleanup, we can try, however, no guarantees that you can trust it will be 100% secure afterwards. In addition, since you have already attempted removal, not knowing what has been done, those attempts may make it more difficult to remove.
My System SpecsSystem Spec

 Trojan win64/ sirefef.b and .J

Thread Tools

Similar help and support threads for2: Trojan win64/ sirefef.b and .J
Thread Forum
Solved Unable to fix Action Center notifications after virus Win64/Sirefef.B System Security
Solved Sirefef!GenC troubling me System Security
Sirefef Removal! System Security
Solved Sirefef.PL + Hupigon-ONX and God's knows what else System Security
trojan virus sirefef removal System Security
MSE took so long to remove 3 types of Sirefef System Security
Trojan.Sirefef virus, problems removing it System Security

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 05:00 PM.
Twitter Facebook Google+

Windows 7 Forums

Seven Forums Android App Seven Forums IOS App

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33