Infected With Alureon.TK & .FB And Sirefef.B & .J Problems With Google Redirects And Booting.

After learning of the connection to the consrv virus, I checked for the signs (positive) and tried various removal methods, including using a WinPE startup disk to clear the assembly directory

I delete them each time but MSE finds more.

After 3 days if a topic is not replied to we assume it has been abandoned and it is closed.

I have attached the Attach.txt log and DDS.txt logs. I have tried various browsers, and the redirect continues. I suppose Microsoft does not have a more "solid" (ie - quick) fix for this trojan yet.

The error has been "SYSTEM.SERVICE.EXPECTION" and "BAD.POOL.CALLER". I have my AV quarantine it, but it still asked me to run it in its sandbox about two or three times.

Several functions may not work. My name is Gringo and I'll be glad to help you with your computer problems.

This was yesterday. I first noticed my computers browser becoming slow loading a few days ago and recently redirecting me to ad sites. In the end, I did a system restore to the day before.

Here's the kicker - MSE finds these trojans, and it seems they come back every 5-16 min. I'll be addressing you by your username, if you'd like me to address you by something else, please let me know!

Microsoft Security Essentials has been repeatedly finding Alureon.TK, Alureon.FB, Sirefef.B and Sirefef.J. I've run TDSS and that has found nothing. I am running windows 7 64bit home edition.

I select the removal option and everything is fine for a time but then MSE pops up again warning me of the same files. Otherwise, Combofix seemed to run OK, and reboots have been much smoother.

I had to finally restore to yesterday to get fully booted up.

I had Microsoft Security Essentials and Zonelab on my computer and used Malwarebytes Antimalware to detect any problem but when scanned they all came back clean. Where is it coming from!?!? Again, I cleared them all, restarted the computer, and when it didn't restart, ran startup repair four times in a row.

My OS is Windows XP Pro with SP3. In subsequent posts, I will posts the files asked for here. My name is Gringo and I'll be glad to help you with your computer problems. But laptop fails booting into Windows afterward. - MSE seems to have blocked the redirects, but sometimes internet get disabled randomly. - Cannot turn fire wall on.

The need for a system restore once MSE removes the threat puzzles me.

AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . After that, the redirects began coming over and over.

I managed to install it and run it but there was an hiccough and it disappeared! - I have no idea why and I cannot get it back and it didn't I found my firewall was off and when I tried to turn it on I got: Windows Firewall can't change some of your settings Error code 0x80070424 Thanks for your help! Then I did system restore, and decided to look for help.

Luckily I was able to use Maxthon browser to visit the actual sites behind the genuine links.

I have now tried to follow the instructions on this site about 'before you post'...


Started by dpeck , Feb 11 2012 10:53 PM

If I need to do anything please let me know, and Thank You.