Trojan win64/ sirefef.b and .J

Beast52702

Aspiring Member
Member
Local time
5:40 PM
Messages
82
Dell laptop has sirefef.b trojan sirefef.j trojan and win32/alureon.TK

These are all trojans.

The laptop has MicSecEssentials, and malwarebytes free version, both of which I put onto the computer after the viruses were there.

system Specs:
Dell Inspiron
intel i3 2130 2.3 ghz
4gb ddr3 ram
hd graphics 3000
Win 7 64

I wanted professional help to deal with these problems and I do not trust many random websites. Please assist! Any help will be greatly appreciated.

-Mike
 

My Computer My Computer

At a glance

Win 7 64bit UltimatePhenom ii 955 OC'd to 3.7ghzGskill RipjawsX 8gb 1600 8-8-8HIS iceq Radeon Hd 7950 1gb 1000/1475
Computer Manufacturer/Model Number
Home Built
OS
Win 7 64bit Ultimate
CPU
Phenom ii 955 OC'd to 3.7ghz
Motherboard
Gigabyte 880g-ud3h
Memory
Gskill RipjawsX 8gb 1600 8-8-8
Graphics Card(s)
HIS iceq Radeon Hd 7950 1gb 1000/1475
Sound Card
Integrated
Monitor(s) Displays
ASUS VS248h-p, LG Flatron 21.5
Screen Resolution
Both 1080P and both 2 ms
Hard Drives
samsung f3 1tb 7200rpm
PSU
XFX 750W XXX edition
Case
Antec 300
Cooling
7 120mm fans, Coolermaster 212+ with push pull
Mouse
Death adder 3500 dpi
Internet Speed
15 mb/s

My Computer My Computer

At a glance

Systems 1 and 2: Windows 7 Enterprise x64, Wi...System 1: i7 [email protected], System 2: AMD FX-41...System 1: 8GB System 2: 8GBSystem 1: ATI FirePro V4800 System 2: Radeon ...
Computer Manufacturer/Model Number
Dell and Custom
OS
Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer
CPU
System 1: i7 [email protected], System 2: AMD FX-4100 Zambezi 3.6G
Motherboard
System 1:Dell 06NWYK System 2: ASUS M5A97 AM3+
Memory
System 1: 8GB System 2: 8GB
Graphics Card(s)
System 1: ATI FirePro V4800 System 2: Radeon HD 6850
Sound Card
System 1: onboard System 2: onboard
Monitor(s) Displays
System1: Viewsonic HDMI 24"
Screen Resolution
System 1: 1920x1080 System 2: 1920x1080
Hard Drives
System 1: Mirrored .5B drives System 2: Seagate Barracuda ST1000DM003 1TB 7200 RPM 64MB Cache SATA 6.0Gb/s
Case
System 1: Dell System 2: Cooler Master
Internet Speed
10 MBPS
I was reading that one of these trojans will edit registry files and that the removal of the virus is complicated until these registry files are fixed.

Is this true? If so, what tool should I use.

Also, the Microsoft security essentials keeps detecting the threats and "successfully" removing them, but then it re-detects them 5 minutes later. What can I do to change this? Will the program that you linked me to be more effective at removing these viruses?

Sorry about all the questions, Please advise

-Mike
 

My Computer My Computer

At a glance

Win 7 64bit UltimatePhenom ii 955 OC'd to 3.7ghzGskill RipjawsX 8gb 1600 8-8-8HIS iceq Radeon Hd 7950 1gb 1000/1475
Computer Manufacturer/Model Number
Home Built
OS
Win 7 64bit Ultimate
CPU
Phenom ii 955 OC'd to 3.7ghz
Motherboard
Gigabyte 880g-ud3h
Memory
Gskill RipjawsX 8gb 1600 8-8-8
Graphics Card(s)
HIS iceq Radeon Hd 7950 1gb 1000/1475
Sound Card
Integrated
Monitor(s) Displays
ASUS VS248h-p, LG Flatron 21.5
Screen Resolution
Both 1080P and both 2 ms
Hard Drives
samsung f3 1tb 7200rpm
PSU
XFX 750W XXX edition
Case
Antec 300
Cooling
7 120mm fans, Coolermaster 212+ with push pull
Mouse
Death adder 3500 dpi
Internet Speed
15 mb/s

My Computer My Computer

At a glance

Systems 1 and 2: Windows 7 Enterprise x64, Wi...System 1: i7 [email protected], System 2: AMD FX-41...System 1: 8GB System 2: 8GBSystem 1: ATI FirePro V4800 System 2: Radeon ...
Computer Manufacturer/Model Number
Dell and Custom
OS
Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer
CPU
System 1: i7 [email protected], System 2: AMD FX-4100 Zambezi 3.6G
Motherboard
System 1:Dell 06NWYK System 2: ASUS M5A97 AM3+
Memory
System 1: 8GB System 2: 8GB
Graphics Card(s)
System 1: ATI FirePro V4800 System 2: Radeon HD 6850
Sound Card
System 1: onboard System 2: onboard
Monitor(s) Displays
System1: Viewsonic HDMI 24"
Screen Resolution
System 1: 1920x1080 System 2: 1920x1080
Hard Drives
System 1: Mirrored .5B drives System 2: Seagate Barracuda ST1000DM003 1TB 7200 RPM 64MB Cache SATA 6.0Gb/s
Case
System 1: Dell System 2: Cooler Master
Internet Speed
10 MBPS
Also I ran the scan tool from microsoft and it did not find anything in quick scan??? yet MSE still reports these trojans??
 

My Computer My Computer

At a glance

Win 7 64bit UltimatePhenom ii 955 OC'd to 3.7ghzGskill RipjawsX 8gb 1600 8-8-8HIS iceq Radeon Hd 7950 1gb 1000/1475
Computer Manufacturer/Model Number
Home Built
OS
Win 7 64bit Ultimate
CPU
Phenom ii 955 OC'd to 3.7ghz
Motherboard
Gigabyte 880g-ud3h
Memory
Gskill RipjawsX 8gb 1600 8-8-8
Graphics Card(s)
HIS iceq Radeon Hd 7950 1gb 1000/1475
Sound Card
Integrated
Monitor(s) Displays
ASUS VS248h-p, LG Flatron 21.5
Screen Resolution
Both 1080P and both 2 ms
Hard Drives
samsung f3 1tb 7200rpm
PSU
XFX 750W XXX edition
Case
Antec 300
Cooling
7 120mm fans, Coolermaster 212+ with push pull
Mouse
Death adder 3500 dpi
Internet Speed
15 mb/s
For what it's worth, I read in a post Kapersky was the only one to remove win32/alureon.T. Again, your mileage may vary. Also, remember not to keep two virus scanners on one system.
 

My Computer My Computer

At a glance

Systems 1 and 2: Windows 7 Enterprise x64, Wi...System 1: i7 [email protected], System 2: AMD FX-41...System 1: 8GB System 2: 8GBSystem 1: ATI FirePro V4800 System 2: Radeon ...
Computer Manufacturer/Model Number
Dell and Custom
OS
Systems 1 and 2: Windows 7 Enterprise x64, Win 8 Developer
CPU
System 1: i7 [email protected], System 2: AMD FX-4100 Zambezi 3.6G
Motherboard
System 1:Dell 06NWYK System 2: ASUS M5A97 AM3+
Memory
System 1: 8GB System 2: 8GB
Graphics Card(s)
System 1: ATI FirePro V4800 System 2: Radeon HD 6850
Sound Card
System 1: onboard System 2: onboard
Monitor(s) Displays
System1: Viewsonic HDMI 24"
Screen Resolution
System 1: 1920x1080 System 2: 1920x1080
Hard Drives
System 1: Mirrored .5B drives System 2: Seagate Barracuda ST1000DM003 1TB 7200 RPM 64MB Cache SATA 6.0Gb/s
Case
System 1: Dell System 2: Cooler Master
Internet Speed
10 MBPS
upon removal of the sirefef.b trojan sirefef.j trojans the computer would not even boot into windows.

I really need some way to fix the registry before removing the virus, as the removal of the virus destroys the files and subsequently does not allow windows boot.

Anyhow, that is what I believe is going on
 

My Computer My Computer

At a glance

Win 7 64bit UltimatePhenom ii 955 OC'd to 3.7ghzGskill RipjawsX 8gb 1600 8-8-8HIS iceq Radeon Hd 7950 1gb 1000/1475
Computer Manufacturer/Model Number
Home Built
OS
Win 7 64bit Ultimate
CPU
Phenom ii 955 OC'd to 3.7ghz
Motherboard
Gigabyte 880g-ud3h
Memory
Gskill RipjawsX 8gb 1600 8-8-8
Graphics Card(s)
HIS iceq Radeon Hd 7950 1gb 1000/1475
Sound Card
Integrated
Monitor(s) Displays
ASUS VS248h-p, LG Flatron 21.5
Screen Resolution
Both 1080P and both 2 ms
Hard Drives
samsung f3 1tb 7200rpm
PSU
XFX 750W XXX edition
Case
Antec 300
Cooling
7 120mm fans, Coolermaster 212+ with push pull
Mouse
Death adder 3500 dpi
Internet Speed
15 mb/s
Hi, Beast52702.

What is going on is, based on the findings of MSE, it appears your computer is infected with a rootkit known as ZeroAccess.

ZeroAccess (Max++) Rootkit (aka: Sirefef) is a sophisticated rootkit that uses advanced technology to hide its presence in a system and can infect both x86 and x64 platforms. ZeroAccess is similar to the TDSS rootkit but has more self-protection mechanisms that can be used to disable anti-virus software resulting in "Access Denied" messages whenever you run a security application. For more specific information about this infection, please refer to:

This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.

If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable. It would also be wise to contact those same financial institutions to appraise them of your situation.

I suggest you take a look at the following link: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?. If you wish to format, there are very helpful tutorials here at Seven Forums on how to proceed.

Should you wish to attempt cleanup, we can try, however, no guarantees that you can trust it will be 100% secure afterwards. In addition, since you have already attempted removal, not knowing what has been done, those attempts may make it more difficult to remove.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Back
Top