Posted 14 June 2012 - 08:49 PM
My PC is infected with the Sirefef trojan.
It's a Windows 7 machine, and I had Microsoft Security Essentials (MSE) running on it.
Two weeks ago, MSE told me I had been infected with the "Win64/Sirefef.Y trojan", and that it had quarantined it. I then had MSE remove the trojan.
However the same trojan kept coming back. Every time I would have it removed, and it would be gone for a while, but then would be detected and quarantined by MSE, and I would have MSE delete it.
Eventually, the trojan caused MSE to shut down, and when I tried to restart MSE, I was told that the program was not installed. I uninstalled MSE and tried to re-install it, but now the PC would reboot after 1 minute, each time preceded by a error message "Windows has encoutered a problem and needs to reboot" or something like that.
I went online to research the problem, could not find much on this malware, and ended up hiring an online malware removal service - Yoocare.com - to clean the computer for me.
Booting into safe mode with networking and running TeamViewer so that they could work on my machine from remote, Yoocare spent a long time, but eventually removed the malware, and my computer worked fine for about a week. Then the same trojan re-appeared. I went back to Yoocare and they removed the virus again, twice, in the space of another week. Each time they told me that the machine was completely cleaned. The last time was a few days ago. Each time the machine worked fine, and I made sure I did not go browsing any bad websites or open any email from unknown senders.
Then yesterday MSE detected a new threat: "JS/BlacoleRef.W" and quarantined it. I had MSE remove the virus.
I also went online and used ESET online scanner to do a scan of my machine (a procedure I had seen the Yoocare people use when they were working on my machine). The ESET scan detected two threats: "Win64/Patched B trojan" and "Win32/InstallCore D application". I had ESET remove those two items as well.
All day today my machine worked fine, without any problem. However, I went out for a while, came back, booted the PC, and found out that MSE was turned off.When I tried to turn it back on, I was told that MSE was not installed, again! I went back to the ESET online scan and am running it now. So far it has already found 3 versions of the trojan: 2 of the "Win64/Sirefef.W", and one "Win64/Sirefef.AE", and has not completed yet. Even if I will have these removed, and anything else the ESET Scan will find, I don't believe that the trojan will be gone from my machine, and will just come back, like the previous times.
So - I really need some help to truly get rid of this problem. I'm not going back to Yoocare, because they have tried several times already and have not been able to root out this thing. Hopefully someone here will be able to help. Thank you very much in advance.