Trojan: dos/alureon.a

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sueet, Dec 12, 2012.

  1. Sueet

    Sueet Private E-2

    Hello, I am looking for help with this trojan. I have read thru many other threads, and mostly they don't help because we can't get anything to run.

    I found a thread here on your site with info about the 64bit win 7 (user states the same issues we have), but the fix listed in that thread states that it is for that specific computer only, so I did all the steps listed there ( http://forums.majorgeeks.com/showthread.php?t=255025 ) and I am attaching the text file generated by the Frst64.exe (Really hoping someone can do for us what they did for him)

    :( Please help, this really sucks.
     

    Attached Files:

  2. Sueet

    Sueet Private E-2

    It won't let me uninstall or change anything :(
     
  3. Sueet

    Sueet Private E-2

    I have done all steps that I COULD do from the read & run me first page, unfortunately, even in safe mode I can NOT run any of the apps. I did manage to run the bios lvl Frst64.exe which I attached the text file from. I do NOT have any idea what else to do, is my only choice now to reformat/reinstall ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have several infections.

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.


    Now run the READ & RUN ME if possible and attach the logs from it.
     
  5. Sueet

    Sueet Private E-2

    Hello, thank you for the reply.

    The computer now doesn't display the dll errors when booted, however we still cannot run any programs, even in safe mode. I am attaching the fixlog.txt that was generated.

    Next step? Thank you in advance for trying to help with this.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Tell me exactly what happens?
    • Can you boot your PC up in normal mode?
    • Do you get to having your Desktop displayed?
    • What exactly happens when you try to run something? What have you tried to run?
    Please run run a full scan with FRST like you did when you were posting your first message. Attach the new log.
     
  7. Sueet

    Sueet Private E-2

    Prior to running the fixlist there were two DLL errors at every startup, those are resolved, Booting up the computer is a little slow, but gets to the desktop just fine, can browse the folders, open text files, pictures, Connecting to the internet (Wireless) takes about 2 minutes and slows the startup process, but otherwise appears to cause no issues.

    The computer will run .txt files, pictures, and certain programs if opened directly from the folder that the program is located (For example, World of Warcraft will only open from "X:Examplefolder/World of Warcraft/WoW64.exe"

    Internet explorer will only run the 64bit version and only from the start menu
    Shortcuts for the most part appear to just flat out not work.

    Most programs unrelated to windows will not open, For example TDSS Killer, Rogue Killer, Norton Antivirus, Spybot S&D the process will open in the Task Manager, Get to between 500 and 1000 kb memory used (Highest Ive seen was 1157) at which point it freezes and then vanishes from the process list, This happens when run normally, or as administrator, same with safe mode, and renaming the files appears to have no effect.

    In the control panel the Add/Remove Programs does not work properly, For example when attempting to comply with one of the things stated in the "Read and run first" post, "Remove all but one antivirus" it opens the uninstaller for a moment, appears to be running, then closes and gives an error along the lines of "Windows Installer Service could not be accessed" (If you need the exact error message let me know, Its not like it isnt a repeatable process to get it to pop up :p) This affects all programs in the list, I manually deleted the adaware folder, but it cant be removed from the list of programs.

    If any other details come to mind Ill share them.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it sounds like you have the ability to run some things. Let's see if you can run the below. Try each step.


    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator



    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've tries them, immediately run the following even if Rkill did not seem to run.

    Try running MGtools per the instructions here > Using MGtools

    Your last log from FRST does show you still have a serious infection that we arleady tried to remove. The below shows
     
  9. Sueet

    Sueet Private E-2

    for Rkill .exe .com and .scr each one a command prompt window flashed open and closed instantly, ran one, tried mg tools, then the next, and then the third.
    MGtools still failed to run, the .pif file returns a 404 error so I cant dowload it.
    Only one of the three I was able to download could be run as administrator (the .exe) the other two had no option for it, but ran through double click anyway

    Sorry for the late reply, I was waiting for my son to help me with this.

    Edit: As a side note, I tried running all the other programs and installers as well (CCleaner installer, Malware Bytes installer, TDSS killer, and so on) still no luck
     
    Last edited: Dec 19, 2012
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the C:\MGtools folder get created? If yes, look in this folder and see if you can run the FixFA.bat program by right clicking on it and selecting Run As Administrator.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also let's try another fix with FRST. I will also have it kill a couple items from Spybot and Adware to make sure they are not getting in the way. Next step may be to remove Symantec.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Sueet

    Sueet Private E-2

    No, no C:\MGtools folder has been created, ran the fixlist, still no luck with any of the programs, or getting MG tools to run, Everything is acting just about the same as it was when we started. More than a little frustrating to be honest :(

    Fixlog is attached
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Indeed!

    Please run run a full scan with FRST like you did when you were posting your first message. Attach the new log. I want to see if we were really able to remove the C:\Windows\svchost.exe file. I tend to doubt it. I believe you do have a partition level infection which has to be fixed before we can get rid of this file. But without being able to run some to the other tools, it is problematic.

    Do you have all important data backed up? You could be heading towards a reinstall. Also attempts to remove this infection could result in making things worse since we cannot run some of the typical tools.
     
  14. Sueet

    Sueet Private E-2

    FRST log is attached.

    For the most part any important data is backed up off the C drive.
    A reinstall will suck though :( Especially since I have no way of getting the driver related information to pre download drivers on my other computer.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the below infection is still present and this is the problem. If we could get your PC to boot and run a couple tools like TDSSKiller, we could probably fix it.

    You can try making the below special boot CD using another computer. Then use it to try an fix the problems. It may or may not work.


    The Kaspersky WindowsUnlocker utility to fight ransom malware
     
  16. Sueet

    Sueet Private E-2

    Finally getting somewhere, Woo. (This is the son speaking :p Sueet is currently baking christmas cookies) Ran the kaspersky CD, ran the windows unlocker followed by the kaspersky scan, found 39 (My jaw dropped, honestly.) trojans, sixteen of which werent found, I'm guessing empty remnants of trojans that tried to install themselves and were blocked.
    I deleted/disinfected the ones that I could and now I can run things in normal boot mode, running scans, and through the whole list of other things, will post any relevant logs that you have previously asked for but we were unable to provide :D
     
  17. Sueet

    Sueet Private E-2

    Theres a few more logs that I'll attach with the next post.
     

    Attached Files:

  18. Sueet

    Sueet Private E-2

    These are the other logs, There are two for Malware Bytes, One was a full scan, the second a quick scan that was run after the full scan.

    Its nice to get everything apparently working again, but I'll let you go over the logs if you like.

    Will notify if anything goes wrong in the near future before a response :)
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looking much better.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 33
    Java(TM) 7 Update 5

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
    C:\Windows\TEMP\*.*
    C:\Users\MorDirn\AppData\Local\Temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap]
    [-HKEY_USERS\S-1-5-21-2000701249-2408814517-837372123-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. Sueet

    Sueet Private E-2

    File/Folder C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml not found.

    Just wanted to note that this entry is likely because I had run Spybot S&D as well while doing all the logs, and it was removed prior to doing the OTM thing.. Hopefully doesnt cause any issues xP
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the READ & RUN ME, you should not be doing anything but what we ask you to do.

    You forgot to tell me how things are working. If everything is okay, continue with the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  22. Sueet

    Sueet Private E-2

    Everything appears to be running grandly, Will proceed with the final steps.
    Also sorry, It didnt occur to me at the time to not run spybot as well, since we had finally gotten somewhere.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent. I glad we were able to fix it without having to reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds