Trojan ALureon.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by bdaly1077, Mar 3, 2013.

  1. bdaly1077

    bdaly1077 Private E-2

    I have the Trojan Alureon.A virus. I did the Read and run first. I will post the logs. However TDSS killer wouldnt finish. It got to the end then I got the blue screen and it said:

    PAGE_FAULT_IN_NONPAGE_AREA

    I had the FBI virus around the same time this happened. I am not sure which I had first but I dont seem to ahve the FBI one anymore. Can anyone help with what I have in my logs?

    THanks

    Bob
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please reboot your PC in safe boot mode and then see if you can get TDSSkiller to complete a scan. Attach the log if it runs.

    Do the below no matter whether TDSSkiller runs or not?

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. bdaly1077

    bdaly1077 Private E-2

    Thank you for replying. TDSS did not run in safe mode either. I do not have a flash drive at the moment sink will have to do that tomorrow. When I get that done I will post the log.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay I will be around later in the evening tomorrow
     
  5. bdaly1077

    bdaly1077 Private E-2

    Ok I ran the scan you asked me to. I will post below.

    I forgot to mention one thing and I am sorry if this changes things. I do not have anything on my hard drive that I need to save. Before I came here I reformatted from the Factory Image on my hard drive. But that did not fix my problem and my Windows 7 backup disk doesnt work for some reason. So if there is an easier or quicker way since I dont have anything I need to save that is ok with me. I am sorry I didnt mention this on my first post, but it was late and I was just sick of dealing with this.

    Also I work full time and am in school full time so if I go a bit between posting replies that is why. I will say if things are fixed or not and I wont leave you hanging. Thanks again for your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try Hitman first. Run it again and this time allow it to fix the Alureon infection and the Win64/Bootkit that it reported. Then immediately reboot your PC. After reboot, run a new scan with Hitman Pro and attach the new log. And then also see if TDSSKiller will run,
     
  7. bdaly1077

    bdaly1077 Private E-2

    Ok. Ran hit man and will post log. TDSS task killer ran and comp didnt crash, but I didnt see a way to get a log. But it said no threats found.
     
  8. bdaly1077

    bdaly1077 Private E-2

    that didnt post the log....lets see if this one does....
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It created one right where the procedure stated.... in your root folder. In fact two logs are probably there. Just do the below which will automatically put them into MGlogs.zip


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. bdaly1077

    bdaly1077 Private E-2

    I am going to run that now, but at this moment it seems much better....it was running hot for a week with ram and CPU being chewed up...not its hardly making a sound.....but goig to run that next scan now!
     
  11. bdaly1077

    bdaly1077 Private E-2

    Ran the scan. It looks like it put the results in the same zip as yesterdays. It says it was modified today so I think that is where it went. Anyway I am going to attach it.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay see if you can delete the below file:

    C:\Windows\svchost.exe

    ONLY delete this one located in the C:\Windows folder!!!!!!!
    Do not attempt to delete any others.

    Let me know if you can get this file deleted or not.
     
  13. bdaly1077

    bdaly1077 Private E-2

    Ok. It deleted. Should I restart?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes reboot your PC and make sure that file does not come back.

    Also tell me how everything is working? If the file does not come back and everything is working okay, I will give you final instructions.
     
  15. bdaly1077

    bdaly1077 Private E-2

    The file didn't come back last night or today. It seems to be much better now.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. bdaly1077

    bdaly1077 Private E-2

    Ok. I will do those steps. I just wanted to say thanks a lot for your help. I would buy you a beer if you were closer to me! Is there a way I can donate to Major Geeks since you guys saved me at least $100?

    THanks again!

    Bob
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. bdaly1077

    bdaly1077 Private E-2

    I will definately spread the good word. And I might get a shirt out of it too! Thanks again for your help!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds