Alureon.e - Please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rebbarr, Jan 2, 2012.

  1. rebbarr

    rebbarr Private E-2

    Hello,

    Thank you for all of the information that I've found on here. Your website has helped me tremendously already. Unfortunately, this Alureon.e isn't going away. I have read all of the alureon threads, but it seems that each case is slightly different. So I ran all of the tools mentioned in your read me first thread and attached them.

    Combofix didn't work. It just ended up freezing my computer for hours on end.

    Thank you for any help that you provide. Happy New Year!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What makes you think you are infected? What is reporting it and what is the exact path to the file?

    You need to uninstall your old Java and install the latest version:
    Java Runtime 7
     
  3. thisisu

    thisisu Malware Consultant

    Code:
    Partition	Disk #0, Partition #3	
    Partition Size	8.64 MB ([COLOR="Red"][B]9,056,768[/B][/COLOR] bytes)	
    Partition Starting Offset	249,990,935,040 bytes	
    
    Bootable  Name                   Size          Type                     
              Disk #0, Partition #0  41094144      Unknown                  
    TRUE      Disk #0, Partition #1  244965288960  Installable File System  
              Disk #0, Partition #2  4984519680    Unknown                  
              Disk #0, Partition [B][COLOR="Red"]#3  9056768 [/COLOR][/B]      Unknown   
    @Tim

    Hidden partition infection / Alureon / TDL4
     
  4. rebbarr

    rebbarr Private E-2

    Hi, Thank you so much for your replies.

    I apologize for not writing HOW I came across this. I have Microsoft Security Essentials and it reported that I have Alureon.e. MSE quarantined it and said to restart the computer to clean it. When I did so, MSE again reported the worm-quarantine-restart. MSE says the worm is located in: boot:\\.\PHYSICALDRIVE0\Partition3 (Type 17).

    Also a side question, would it have been safe to just delete Partition 3 if I knew that to be the worm?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that explains it. I wasn't finding anything in one of your logs, but it is evident in the sysinfo log.

    Do you have your XP CD? If so, let;s do this:

    Preferably from a clean computer, I need you to download: gparted-live-0.10.0-3.iso (115.1 MB)
    Windows XP Recovery Console rc.iso

    Create a bootable CD, 1 for Gparted and 1 for the Windows XP Recovery Console, from the ISO images. You can use ImgBurn do this.

    Now boot off of the newly created Gparted CD.

    http://img829.imageshack.us/img829/5772/gpartedsplash.th.png
    You should be here...
    Press ENTER

    http://img5.imageshack.us/img5/7286/gpartedkeymaps.th.png
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]

    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is Partition Disk #0, Partition #3
    Partition Size 8.64 MB (9,056,768 bytes)
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png

    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png

    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    Is "boot" next to your OS drive?

    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png

    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.

    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.

    Now reboot from the Windows XP Recovery Console CD and execute the following commands:


    • fixmbr \Device\HardDisk0
    • fixboot c:
    • exit


    Once back in Windows.

    Download MBRCheck.exe to your desktop.

    • Be sure to disable your security programs
    • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
    • A window will open on your desktop
    • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
    • If nothing unusual is found just press Enter
    • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
    • Attach that file.
     
  6. rebbarr

    rebbarr Private E-2

    Thank you Tim. I just did G-parted and deleted the 8.64 partition like you said. Then, I tried to do the window recovery console cd. I pressed R to get to the command prompt and entered 3 commands.

    When I did the fixmbr \Device...one, it said the Old Master Boot could not be read.

    So I did the fixboot c: and it asked if I wanted to create something - some kind of bootable drive or something. I said no. But then I went through the whole process below again, and pressed yes the second time. I know, I probably messed the whole thing up.

    Then it took me back to the Console with the 3 options - windows XP setup was one of them. I exited and tried to boot the computer back up But it won't boot now because it said XP is not loaded on the computer. So I went back to the windows recovery console and tried to install XP. An error came up that says "Setup cannot find the End User Licensing Agreement (EULA)" and setup cannot continue.

    I know I probably did a bunch of things wrong but I have no idea what that is.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do that while in G-parted?
     
  8. rebbarr

    rebbarr Private E-2

    Yes I did. It was already there when I did it.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me consult with my colleagues. Hang in there.
     
  10. thisisu

    thisisu Malware Consultant

    Hello rebbarr,

    Please explain in detail what actions you took here.
     
  11. thisisu

    thisisu Malware Consultant

    Nevermind, if you were using the Recovery Console CD for that then you wouldn't have been able to install XP. Which explains what you got that EULA notice.
     
  12. thisisu

    thisisu Malware Consultant

    Boot back into the recovery console and type the following command:
    • bootcfg /list
    Note: There is only a SPACE between 'bootcfg' and '/'

    Let me know what text appears after you have entered that command and pressed ENTER.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds