boot sector virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by IcemanGER, Oct 26, 2010.

  1. IcemanGER

    IcemanGER Private E-2

    I have BOO/Alureon.A on my Win 7 64bit Laptop.
    Tried several procedures without any luck.

    biggest problem is that combofix doesn't run on it !

    any help is highly appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the following:
    READ & RUN ME FIRST. Malware Removal Guide

    Then:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  3. IcemanGER

    IcemanGER Private E-2

    ran the TDSSKiller.exe !
    laptop reboots into a BSOD now. tried last known good config, system restore.....

    can't get into save mod either.......
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What OS is it? XP, Vista, Win7? Do you have OS CD's?
     
  5. IcemanGER

    IcemanGER Private E-2

    it's win 7 64bit. i have a couple CD's 32/64. they should work.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can either try using the disc to work in the recovery environment or to repair install. Which way are you wanting to proceed?
     
  7. IcemanGER

    IcemanGER Private E-2

    looks like i only got the 32bit disc. already tried to use the recovery but comes up with a different version.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. IcemanGER

    IcemanGER Private E-2

    ok, that's done. booting the repair disc now.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If trying the Fix Startup doesn't work, we may need to get into the RC and try it that way. Let me know how it goes.
     
  11. IcemanGER

    IcemanGER Private E-2

    repair disc gives me an error.
    Status: 0xc00000e9
    Info: an unexpected I/O error has occurred

    i burned the iso twice. still the same error
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what is wrong with the disc, but it is looking like you may need to borrow a Win7 64 bit disc at this point.
     
  13. IcemanGER

    IcemanGER Private E-2

    exactly the same error with the 32bit disc.
     
  14. IcemanGER

    IcemanGER Private E-2

    so, i downloaded a full version of win7 64bit and when i get into the system restore option it is telling me the same. this copy of windos is not compatible with the one installed !!!
     
  15. IcemanGER

    IcemanGER Private E-2

    i'm reinstalling windows. too bad. was hoping to fix it. :tired
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to hear that. Were you able to save any of your personal info and data? When you ran TDDSKiller, did you choose cure or delete and do you recall what it found?
     
  17. IcemanGER

    IcemanGER Private E-2

    yea, i don't recall what it found, but i double checked with your instruction before i hit OK. "cure" was set !
    there wasn't much personal info on the machine. i could have taken the drive out and used my desktop to get the data off of it. it was my buddies machine btw. 3 weeks old.
    no big deal, data wise.

    thanks for your help, anyways. too bad it didn't work out this time.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's a rare occurrence that TTDSKiller will kill a system. But good to know you didn't have any problems with doing a reinstall. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds