Hit by Trojan:DOS/Alureon.A

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Vaio User, Feb 18, 2012.

  1. Vaio User

    Vaio User Private E-2

    Seems like I was hit by the Trojan:DOS/Alureon.A. I started having problems on the 16th but it was still working. Last night after a system restore it recommended a full system scan, which I performed with Norton, which had to redownload its update due to the system restore. After updating and performing the full system scan, it found this trojan virus and removed two instances but when attempting to remove the third one it went to the blue screen and displayed the message that it was shutting down to prevent system damage. Since then when it boots it receives a startup error and wants to launch startup repair but it only gets stuck at the repair screen for hours and I have to remove the battery to start over. When trying to start it normally, it loops back to the same startup error screen. I kept trying to use the startup repair until it finally told me that it could not repair automatically.

    I read "READ ME FIRST INFO" but I cannot perform any steps as I cannot get it to boot normally. I looked at other forums on my secondary computer, where I was able to download the Farbar Recovery Scan Tool x64 on my USB drive and run the program. Attached is the FRST.txt log, as requested to another user (Seems like it won't let me rettached as it is in my welcome center thread). Also, I tried to download TDSS Killer & Rootkit buster from your site on my USB drive but received the following error in command prompt: the subsystem needed to support the image type is not present.

    Any help will be appreciated my VAIO has been rendered unusable!

    Also my details - Windows 7 Ultimate 64 bit w/Norton Antivirus Software used
     
  2. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, Vaio User!

    I found your attachment in the Welcome Center and have a fix for you.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    Now continue with this procedure: How to Remove Trojan:DOS/Alureon.A
     

    Attached Files:

  3. Vaio User

    Vaio User Private E-2

    Thanks Thisisu,

    With your help this is the first time I reached my desktop in over 24 hours! I used the fixlist.txt you provided and followed the instructions given. Attached is the fixlog.txt requested and I ran TDSS killer, the MBRCheck, went through allt he steps in the "READ & RUN ME First" section; however, in the Windows 7 Cleaning procedures, I could not get combofix to download because Norton detected a trojan with it and quarantined it (i downloaded these files on my secondary computer and moved to USB drive). The fix log, TDSS killer & MBRcheck logs are attached and i will reply to this with the cleaning logs.

    My computer seems to working great again and I'll let you know if anything happens ~ Thanks a bunch!:-D

    Happy VAIO User :wave
     

    Attached Files:

  4. Vaio User

    Vaio User Private E-2

    Attached are the cleaning logs, as promised, except for combox fix as previously explained.

    Thanks!
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    Glad to hear that :)
    You should have disabled Norton before attempting to download / run ComboFix. But if you are not experiencing any problems now it may not be necessary.
    You're welcome. One more thing I would recommend is completing the following:

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Re-scan with TDSSKiller with the parameters you used before.
    This time if TDSS File System appears, delete it!
    Then attach the latest TDSSKiller log. (How to attach)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds