Alureon.A infection - nothing will open

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bcurrey, Dec 17, 2011.

  1. bcurrey

    bcurrey Private E-2

    Yesterday I tried opening IE and Firefox and nothing happened. I ran a virus scan with MSE and it found the lovely TROJAN:DOS/Alureon.A.

    MSE told me I needed to download their system boot sweeper program. I did that, and it scanned the system and found no issues.

    I went back into the regular MSE and ran it, and it still found the trojan.

    I downloaded TDSSKiller and renamed it. Tried running it and it I just got a windows pop up asking if I trusted the program. I click yes, and nothing happens.

    I tried downloading Malware Bytes, and renamed it...same thing - pop up message and then nothing.

    I then tried the rkiller file. Again, nothing.

    The only files that will open on the PC is MSE, Photoshop, Lightroom, and folders.

    Any ideas? I'm at a loss. Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Which version of Windows are you running?
     
  3. bcurrey

    bcurrey Private E-2

    Oh yea, I guess that's a slightly important piece of info.

    I'm running Windows 7 on a dell desktop.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is always important to know the OS version.


    Click Start, All Programs, and then scoll as nessary until you see he Accessories folder and select it. You see something like below.

    http://forums.majorgeeks.com/attachment.php?attachmentid=170564&thumb=1&d=1324150745

    Right click on the little black icon saying Command Prompt and select Run As Administrator.

    A command prompt window should open with a title of Administrator:Command Prompt. Do you get this?? If yes, continue with the below.

    Enter the below command into the command prompt window and hit enter>

    tasklist

    Did you get a list of running processes? If yes, continue.

    Now enter the command as below:

    tasklist > proclist.txt


    This will put the running process list into the proclist.txt file in your C:\Users\useraccount folder ( where useraccount is your user name ), Attach this proclist.txt file to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. bcurrey

    bcurrey Private E-2

    I was able to see the tasklist, but when I tried sending it to the last command, it said access was denied. I was able to copy and paste everything from the command screen, so hopefully this is everything the proclist.txt will give you.

    Let me now if it isn't.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because for some reason it open up the command prompt in the system32 folder. Did you run it exactly how I requested from Accessories and as Administrator?

    Either way, no bad processes are showing there.

    See if you can follow the instructions in the below to run MGtools

    Using MGtools
     
  7. bcurrey

    bcurrey Private E-2

    I downloaded MGtools. I followed the directions and disabled everything. I rebooted. I click on run as administrator, and nothing happened. I searched my system for the MG folder it was suppose to create, but nothing is there.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where exactly did you save the MGtools.exe file to?


    Also Click Start, All Programs, and then scoll as nessary until you see he Accessories folder and select it. You see something like below.

    http://forums.majorgeeks.com/attachment.php?attachmentid=170564&thumb=1&d=1324150745

    Right click on the little black icon saying Command Prompt and select Run As Administrator.

    A command prompt window should open with a title of Administrator:Command Prompt. Do you get this??
    What does the prompt in the window show? Is it C:\Windows\system32>

    Just keep this command prompt window open if it worked, but just come back and answer my questions.
     
  9. bcurrey

    bcurrey Private E-2

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my first question in my last post?
     
  11. bcurrey

    bcurrey Private E-2

    Sorry, it is saved in the C:\ drive. Not in any folders.

    I go to My Computer, click on C drive and it's there in the list.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, then in the command prompt window you have open, do the below.


    Enter the below commands at the command prompt each followed by the enter key. Try each command!!!! The bold black are commands. The purple/brown is merely informational. Tell me what happens at each step especially if something fails to work.
    • NOTE: If you are running a 64 bit version of Windows, instead of typing GetRunKey and ShowNew in the below, use GRK64 and SN64
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    nwktst <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    getnetinf <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    analyse <-- this will try to run TrendMicro Hijackthis. Click Twice on the Accept button to accept the license agreement if it shows. Then run a scan and save a log. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  13. bcurrey

    bcurrey Private E-2

    I am running windows 64.

    I tried each command.

    cd \MGtools came back with "The system cannot find the path specified."

    All the other commands came back with:

    'COMMAND' is not recognized as an internal or external command, operable program or batch file
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. In the command prompt window enter each of the below.

    cd C:\ << your prompt should change to c:\>

    mgtools.exe << this attempts to run mgtools. What happens?
     
  15. bcurrey

    bcurrey Private E-2

    Nothing happens. It just goes back to the c: prompt. When I enter dir to look at the files there, I see the MGtools.exe file.


    Not related to me enter these commands, but in watching my mouse on screen - every 2-3 seconds, it changes to a little circle like it's thinking, but nothing ever happens.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the below will run.

    Download OTL by Old Timer and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif

    • Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
      Code:
      netsvcs
      drivers32 
      %SYSTEMDRIVE%\*.*
      %systemroot%\Fonts\*.com
      %systemroot%\Fonts\*.dll
      %systemroot%\Fonts\*.ini
      %systemroot%\Fonts\*.ini2
      %systemroot%\Fonts\*.exe
      %systemroot%\system32\spool\prtprocs\w32x86\*.*
      %systemroot%\REPAIR\*.bak1
      %systemroot%\REPAIR\*.ini
      %systemroot%\system32\*.jpg 
      %systemroot%\*.jpg 
      %systemroot%\*.png 
      %systemroot%\*.scr
      %systemroot%\*._sy
      %APPDATA%\Adobe\Update\*.*
      %ALLUSERSPROFILE%\Favorites\*.*
      %APPDATA%\Microsoft\*.* 
      %PROGRAMFILES%\*.*
      %APPDATA%\Update\*.*
      %systemroot%\*. /mp /s
      CREATERESTOREPOINT
      %systemroot%\System32\config\*.sav 
      %PROGRAMFILES%\bak. /s
      %systemroot%\system32\bak. /s
      %ALLUSERSPROFILE%\Start Menu\*.lnk /x 
      %systemroot%\system32\config\systemprofile\*.dat /x
      %systemroot%\*.config
      %systemroot%\system32\*.db
      %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
      %USERPROFILE%\Desktop\*.exe
      %PROGRAMFILES%\Common Files\*.*
      %systemroot%\*.src
      %systemroot%\install\*.*
      %systemroot%\system32\DLL\*.*
      %systemroot%\system32\HelpFiles\*.*
      %systemroot%\system32\rundll\*.*
      %systemroot%\winn32\*.*
      %systemroot%\Java\*.*
      %systemroot%\system32\test\*.*
      %systemroot%\system32\Rundll32\*.*
      %systemroot%\AppPatch\Custom\*.*
      %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
      %PROGRAMFILES%\PC-Doctor\Downloads\*.*
      %PROGRAMFILES%\Internet Explorer\*.tmp
      %PROGRAMFILES%\Internet Explorer\*.dat
      %USERPROFILE%\My Documents\*.exe
      %USERPROFILE%\*.exe
      %systemroot%\ADDINS\*.*
      %systemroot%\assembly\*.bak2
      %systemroot%\Config\*.*
      %systemroot%\REPAIR\*.bak2
      %systemroot%\SECURITY\Database\*.sdb /x
      %systemroot%\SYSTEM\*.bak2
      %systemroot%\Web\*.bak2
      %systemroot%\Driver Cache\*.*
      %PROGRAMFILES%\Mozilla Firefox\0*.exe
      %ProgramFiles%\Microsoft Common\*.*
      %ProgramFiles%\TinyProxy.
      %USERPROFILE%\Favorites\*.url /x
      %systemroot%\system32\*.bk
      %systemroot%\*.te
      %systemroot%\system32\system32\*.*
      %ALLUSERSPROFILE%\*.dat /x
      %systemroot%\system32\drivers\*.rmv
      dir /b "%systemroot%\system32\*.exe" | find /i " " /c
      dir /b "%systemroot%\*.exe" | find /i " " /c
      %PROGRAMFILES%\Microsoft\*.*
      %systemroot%\System32\Wbem\proquota.exe
      %PROGRAMFILES%\Mozilla Firefox\*.dat
      %USERPROFILE%\Cookies\*.txt /x
      %SystemRoot%\system32\fonts\*.*
      %systemroot%\system32\winlog\*.*
      %systemroot%\system32\Language\*.*
      %systemroot%\system32\Settings\*.*
      %systemroot%\system32\*.quo
      %SYSTEMROOT%\AppPatch\*.exe
      %SYSTEMROOT%\inf\*.exe
      %SYSTEMROOT%\Installer\*.exe
      %systemroot%\system32\config\*.bak2
      %systemroot%\system32\Computers\*.*
      %SystemRoot%\system32\Sound\*.*
      %SystemRoot%\system32\SpecialImg\*.*
      %SystemRoot%\system32\code\*.*
      %SystemRoot%\system32\draft\*.*
      %SystemRoot%\system32\MSSSys\*.*
      %ProgramFiles%\Javascript\*.*
      %systemroot%\pchealth\helpctr\System\*.exe /s
      %systemroot%\Web\*.exe
      %systemroot%\system32\msn\*.*
      %systemroot%\system32\*.tro
      %AppData%\Microsoft\Installer\msupdates\*.*
      %ProgramFiles%\Messenger\*.*
      %systemroot%\system32\systhem32\*.*
      %systemroot%\system\*.exe
      HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs
      /md5start
      /md5stop
      
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long..
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Just close these notepad windows and attach the two log files to your next message.
     
  17. bcurrey

    bcurrey Private E-2

    It won't run. :(

    I appreciate all your help so far. I'm decent with computers, but you are waaay beyond me.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you boot your computer in safe mode?

    If you can, then see MGtools.exe and also the OTL scan will run in safe mode. Also check to see if Malwarebytes will run in safe mode. Each time you try to run something, make sure you tell me exactly what happens. Don't just say "it won't run". Please tell me of any error messages received or that when you right click and select Run As Admin , nothing at all happens....etc. I need to have an exact idea of what is happening.
     
  19. bcurrey

    bcurrey Private E-2

    I booted in safe mode with command prompt. I went into the c drive and was unable to get any of those programs to run.

    when i'm in that directory, i type:

    C:\>otl.exe

    when I press enter, a line is skipped and i'm back at a new prompt c:\>


    It did that for all the programs.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From a command prompt window if you type the below and hit enter, does a new Windows Explorer window open?

    explorer

    If yes, see if you can rename, MGtools.exe to explore.exe and then see if it will run.

    It is starting to look like you have new type of TDL infection.


    Also does compmgmt.msc run if enter into a Run box?
     
  21. bcurrey

    bcurrey Private E-2

    I'll give it a try tonight when I get home.

    So if nothing works, will I have to go with a hard drive reformat?


    Looks like another user on here just got infected with this as well. I just came across his thread.

    http://forums.majorgeeks.com/showthread.php?t=249208

    Thanks!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If we cannot get anything at all to work then yes that would be the case. However as you noticed in the thread you point out, there are still other options. The FSRT program was where I was soon headed with you to. Either this or one of the special rescue disks which can be used to boot your PC and run scans offline. Some of these disks are mentioned at the end of the below link:

    Alternative Scans

    But FSRT would be my preferred next step.
     
  23. bcurrey

    bcurrey Private E-2

    Finally, a tiny bit of positive news.

    At the command prompt, I typed explorer and a window explorer screen did pop up.

    I renamed the mgtool file to explorer.exe and then ie.exe and neither worked. It paused for a second after pressing enter, and then just skipped to a new command line.

    I did type compmgmt.msc in the run box, and the computer management screen DID appeared.

    I am still operating in safe mode.
     
  24. bcurrey

    bcurrey Private E-2

    I just ran the FRST program that is mentioned in the other topic that appears to have the same issue as me. Attached are the results.

    Appreciate your help!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no signs of malware in this log. The only questionable item is that FSRT could not access part of the registry. Did you run this after you booted into the System Recovery Environment?

    Does System Restore work? If so, you may want to try using it.
     
  26. bcurrey

    bcurrey Private E-2

    I was in safe mode when I ran that and not the System Recovery Environment. I'll try it when I get home tonight.

    I did look at system restore, but there are no dates prior to the computer issues.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! That explains the registry issue. It has to be run as stated in the instructions from the System Recovery Environment.
     
  28. bcurrey

    bcurrey Private E-2

    I just ran the FRST program in System Recovery mode. Attached are the results. Thanks!
     

    Attached Files:

  29. bcurrey

    bcurrey Private E-2

    I just did the scan in mentioned in the other thread. The system found no integrity issues.
     
  30. bcurrey

    bcurrey Private E-2

    Pretty significant breakthrough tonight! :hyper

    I kept looking around on my computer trying to find something that didn't look right. I ended up trying to open a browser again. When I tried opening IE, I got a message saying the program had been moved or deleted and did I want to delete the shortcut.

    I looked at the path for the shortcut. It was in the normal spot. I then went into my c: drive and went to the path. The path is still exists! I tried opening explore.exe and nothing happened.

    As I was exiting out, I noticed there were 2 IE folders. One for 64 bit, and then 32. I went into the 32 bit folder, and clicked on explore.exe, and it OPENED! I was able to get on the web. This is the first program that has opened since I became infected

    I still can't open any other exe files, but I am online trying to get a scan completed or something. Any ideas on what to try now would be greatly appreciated!!!
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From what you are discribing, it is possibly you have an infection that hides files, folders, etc. We have had a bunch of these in the past but perhaps you have new form. The below unhide program has been helpful with these in the past. See if you can get it to run.


    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?
     
  32. bcurrey

    bcurrey Private E-2

    I tried the unhide.exe and it wouldn't open. It just sits there.

    It appears that anything in the Program Files (x86) folder will not work. The problem is that IE 9.0 is the only useful program installed in folder. I've tried copying and pasting some of the files suggested in this thread into that folder, and none will open.

    I was able to get to Bitdefender.com and do an online scan. It didn't find any errors though. Below is the log file that it gave me. Sorry I can upload it at work and had to copy & paste.


    [Edit by chaslang] Inline log attached
     

    Attached Files:

    Last edited by a moderator: Dec 23, 2011
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since IE9 opens up, tell me what happens if you copy and paste the below into the Address Bar and hit enter

    file://c:\Program Files (x86)

    • Does a Windows Explorer windows open with the above folder show?
    • If yes, right click on the folder and select Properties.
      • What do you see for Attributes? Is Read-only checked? Is Hidden checked?
      • Click the Security tab and tell me what you
        see listed in the Group or user names box while at the same time observing what Permissions for that user name are shown in the lower box. Be sure to scroll in these boxes as necessary to see all content.
      • For example: Two of the names should be SYSTEM and Users ( pcname\Users ) where pcname is the name of your computer and I want to see permissions. So you should give me a list like below but for all user names seen.
    For user name = SYSTEM
    Permissions:
    Full control
    Modify
    Read & execute
    List folder contents
    Read
    Write
    Special permissions - Allowed

    For user name = Users ( pcname\Users )
    Permissions:
    Full control
    Modify
    Read & execute - Allowed
    List folder contents - Allowed
    Read - Allowed
    Write
    Special permissions
     
  34. bcurrey

    bcurrey Private E-2

    The folder did open when I entered that into explorer. However, I just want to point out that I could see this folder when I went thru My Computer. It was only when using the IE icon on my desktop that it couldn't find the files. Though I know that icon was working fine last week.

    When looking at the attributes - Read Only has a shaded box. It appears there are 3 options for this, check, unchecked, and the box. The hidden box is unchecked.

    Here are the groups within the security section. I'm only going to list the actions that are Allowed for each group.


    CREATOR OWNER
    Special Permissions

    SYSTEM
    Special Permissions

    ADMINISTRATORS
    Special Permissions

    USERS
    Read & Execute
    list folder contents
    read

    TRUSTED INSTALLER
    List folder contents
    Special Permissions
     
  35. bcurrey

    bcurrey Private E-2

    One more thing. I started this thread on 12/17 and mentioned I started having issues on 12/16. Last week when I looked at system restore, there were no restore points. Today when I look, I have one from the night of 12/15. Should I give that a try?
     
  36. bcurrey

    bcurrey Private E-2

    I did a system restore. It helped, as now my internet speed is back to normal. Last night I was downloading at a rate of about 1,000 KB per sec. Now I'm back up to 1-2 MB's.

    I still can't get anything to open except by going to Program Files and opening IE. I went back to Bitdefender and ran an online scan and it did find a virus. However, I can't clean it because the system won't allow me to install anything. Attached is the log.
     

    Attached Files:

  37. bcurrey

    bcurrey Private E-2

    I was able to get the Microsoft online security scan to run. It took almost 2 hours for it to finish. It found 17 infected files - 2 related to Alureon and another one. It cleaned everything, and I restarted, but I'm still having trouble opening stuff.

    Thus far, I've been able to get the Microsoft scanner and the Bitdefender to run. I've tried SEVERAL others, but when I choose "run" or "save and run" they just don't run.

    Any more ideas? I feel like we are getting close to solving this. Thanks!
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not to sure about that. We still are not really getting anywhere with this. We need to be able to run some useful scans that produce logs so that we can hopefully find the reason for your problems.

    Earlier we did determine that you could open up a command prompt window. Please do this again ( don't forget to Run As Administrator ). At the command prompt, type the below command each follow by the enter key and tell me what happens after each one. Note that the bold black is the command. The bold brown is just FYI or questions.

    • cd \ << There is a space after the cd
    • attrib
    • dir > flist.txt
    • dir /S C:\users >> flist.txt << There is a space after the dir and before the C:
    Does a c:\flist.txt file now exist? If yes, attach it here.
     
  39. bcurrey

    bcurrey Private E-2

    I was able to run the file. It's pretty big. Thanks!
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the attrib command run and did it show a list of files?
     
  41. bcurrey

    bcurrey Private E-2

    Yes, it ran and here's the list:



    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>cd \

    C:\>attrib
    A C:\aaw7boot.log
    A HR C:\dell.sdr
    A C:\eula.1028.txt
    A C:\eula.1031.txt
    A C:\eula.1033.txt
    A C:\eula.1036.txt
    A C:\eula.1040.txt
    A C:\eula.1041.txt
    A C:\eula.1042.txt
    A C:\eula.2052.txt
    A C:\eula.3082.txt
    A C:\flist.txt
    A C:\globdata.ini
    A SH I C:\hiberfil.sys
    A C:\install.exe
    A C:\install.ini
    A C:\install.res.1028.dll
    A C:\install.res.1031.dll
    A C:\install.res.1033.dll
    A C:\install.res.1036.dll
    A C:\install.res.1040.dll
    A C:\install.res.1041.dll
    A C:\install.res.1042.dll
    A C:\install.res.2052.dll
    A C:\install.res.3082.dll
    A SH C:\pagefile.sys
    A C:\vcredist.bmp
    A C:\VC_RED.cab
    A C:\VC_RED.MSI
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can do the below.


    Now download this subinacl and save it to either your root folder ( C:\ ) or if you cannot save it there, save it to your Desktop.

    Now download this perm.cmd and save it to the exact same location you saved subinacl to.

    Now right click on perm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.

    Once it finishes, reboot your PC..... that is assuming it runs.
     
  43. bcurrey

    bcurrey Private E-2

    This would not run. I chose the run as admin option and nothing happened.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me exactly where you saved both files to.
     
  45. bcurrey

    bcurrey Private E-2

    I saved them to the desktop
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on subinacl.exe and select Properties and then the Security tab. What permissions are setup for your user account and who is the Owner.
     
  47. bcurrey

    bcurrey Private E-2

    Just tried running it again, and the black command prompt screen came up for a second, and then went away. Didn't see anything other than that.

    The groups on the security tab are:

    System
    My User profile
    Admin

    All three have the same permissions - full control, modify R&E, read, write
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are there other user accounts on this PC? If so do any of them work properly?

    We are running out of options and you may have to cut your losses and backup what you can and reinstall. External scans from special boot CDs may be possible, but I'm not sure they would find anything. It is also possible that if they did find a serious infection that is causing this, that the act of removal could make you PC unbootable.
     
  49. bcurrey

    bcurrey Private E-2

    No clue is this is a possibility, but thought I'd throw it out there.

    Is it possible for me to install an anti-virus on my netbook, connect it to my infected computer, and run a virus scan off the netbook?

    I'm thinking of it similar to how you can search for a file across multiple network drives, or even run virus scans to include scanning external drives.

    Thanks!
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is possible. Even removing your hard disk from this infected compter and slaving it to another computer to be scan is a possibility. However you have to understand the risks too:
    1. It is possible that nothing major will be found.
    2. It is also possible that something may be found and the scanner may delete it but since the scanner will not be running from the Windows environment of the PC that is infected, it may remove files that are necessary for your Windows Operating System to even boot up. Thus the end result could be your PC is unbootable and you had better transfer import data to you other PC first.
    3. Similar scanning operations can also be performed using your infected PC by making specialized CDs meant for this purposed. The same dangers as mention in number 2 above would still exist. Example CDs are mentioned at the bottom of the below link
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds