Trojan horse can't be removed.

Yesterday i log in and my peerblock program gives me an error saying it’s missing Base Filtering Engine, IKE and AuthIP IPsec Keying Modfules, IPsec Policy Agent. So i look in the services and see the Base Filtering Engine missing. I installed a new one and am able to use peerblock but i see that Microsoft Security Essentials is disabled and or missing along with the firewall. So i have no protection now.

Malwarebytes report
Trojan.Dropper.BCMiner File C:\Windows\Installer{20b8dfa8-d532-4621-8386-b3f411aed8bb}\U\00000008.@
PUP.Blabbers Registry Value HKCR\protocols\Handler\base64|CLSID Value: base64|CLSID
PUP.Blabbers Registry Key HKCR PROTOCOLS\HANDLER\BASE64
PUP.Blabbers Registry Value HKCR\protocols\Handler\chrome|CLSID Value: crome|CLSID
PUP.Blabbers Registry Key HKCR PROTOCOLS\HANDLER\CHROME
PUP.Blabbers Registry Value HKCR\protocols\Handler\base64|CLSID Value: prox|CLSID
PUP.Blabbers Registry Key HKCR PROTOCOLS\HANDLER\PROX
PUP.Blabbers Registry Value HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Browser companion helper value: Run|Browser companion helper

Reimage report

c:\windows\system32\services.exe — Win64/Patched.B.a.k.a W32/Patched.UA

I tried a lot of other programs and they say Win32Sirefef and HEUR:Backdoor.Win64.Generic
I have looked around and tried looking in the reg but found nothing they say would be in it.
I tried many programs from spyHunter,speedPC Pro,Sophos Viruse Removal Tool, CCleaner, PandaCloudCleanerm Panda CloudAntivirus, ReimageRepair, Pareto_AV, to name a few but they don’t work for one reason or another.

I had avast installed and running while this happen. So if anyone could help me in getting rid of this i would make my day!

I’m using windows 7 if you need more information let me know i will post it.

You should not have two antivirus applications on your system at the same time so you’ll have to decide which one you would like to keep ( you know my recommendation :slight_smile: ) once you have removed MSE and if still having the issue then reply back here.
I’d also suggest running removal tools for all the other AV’s you have tried as well, many removal tools can be found here http://singularlabs.com/uninstallers/security-software/

Okay removed some programs and MSE. I was in safe mode and had to boot into normal to remove it. I have
Ad-Aware Browsing Protection, Avast, Malwarebytes Anti-Malware, Reimage Repair, SpyHunter, SUPERAntiSpyware installed what ones do i remove? I finished the scan for Avast in safe mode and it picked up 8 viruses. Looks like it made changes to avast as i only have one thing running in real-time shields (script shield).

C:\Windows\assembly\Gac_32\Desktop.ini Threat: Win32:Sirefef-PL [Rtk]
C:\Windows\assembly\Gac_64\Desktop.ini Threat: Win32:Sirefef-PL [Rtk]
C:\Windows\Installer\ Threat:Win32:Malware-gen
C:\Windows\Installer\ Threat:Win32:Malware-gen
C:\Windows\Installer\ Threat:Win32:Malware-gen
C:\Windows\Installer\ Threat:Win32:Downloader-PKU [Trj]
C:\Windows\Installer\ Threat:Win32:Malware-gen
C:\Windows\assembly\Gac_32\Desktop.ini
That’s from a full scan in safe mode for Avast. I’m doing another full scan with avast now to see if it got them or if its still here. 3 to 6 hours. I’m thinking about uninstalling and re installing Avast what do you think?

Malwarebytes keeps popping up with warnings about blocking connections to an IP so i don’t think the virus is gone yet.

Ad-Aware and SpyHunter not needed, the others are fine.

If a repair of avast doesn’t fix the non working shields then the best option would be a clean install, i’d also suggest reading http://forum.avast.com/index.php?topic=53253.0 and supplying the logs required for a malware expert to look over as it seems you maybe infected.

Yes this will need that assistance of a malware removal specialist to remove the underlying infection, so follow the advice in the link posted by craigb in his post above mine.