Alureon.A

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hpdv8, Mar 16, 2012.

  1. hpdv8

    hpdv8 Private E-2

    Hello your site comers highly recommended. Thanks for being such a fantastic help to people like me.

    I ran Microsoft Security Essentials and found Alureon.A and I'm unable to run programs. I read several of posts so I think I have attached what you need to help me.

    Machine: HP DV8 64bit
    Opersting System: Windows 7 Premium
    Antivirus Program and Security Installed:
    MSE, Adaware, Spybot Search and Destroy, Ccleaner, Mailwarebytes, TDSSKiller

    Thanks in advance for any help you can provide
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, hpdv8!

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally and run programs.
     

    Attached Files:

  3. hpdv8

    hpdv8 Private E-2

    Ok I did as you requested.

    Fixlog.txt is attached.

    I'll wait for further instructions.

    Thank you!
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

  5. hpdv8

    hpdv8 Private E-2

    I'm on it right now... Thanks to you I'm now able to run programs, so I should now be able to do everything needed now. Can't wait to get this off my computer.
     
  6. hpdv8

    hpdv8 Private E-2

    Attached Files:

  7. hpdv8

    hpdv8 Private E-2

    Ok I've done all the things listed and attached the log reports.

    I think the system is clean, but I'll wait for further instructions before trying to open Outlook or any web browsers.

    Thanks so much for this!
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Re-scan with TDSSKiller with the parameters you used before.
    This time if TDSS File System appears, delete it!
    Then attach the latest TDSSKiller log. (How to attach)

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 22 (outdated)
    • Java(TM) 6 Update 24 (outdated)

    http://img195.imageshack.us/img195/9049/javaz.gif Now install the current version of Sun Java from: jre-7u3-windows-x64.exe

    __

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Be safe :)
     
  9. hpdv8

    hpdv8 Private E-2

    Ok I just did my last ComboFix and attached the log file.

    Deleted the old Java's and installed the new one..

    Now I'm deleting some tools..

    I think you nailed it. Thank you so much.
    One last thing, do you think I should scan for issues in the registry with Ccleaner now?

    Thank you again for all your help.
    This site is awesome.
     
  10. hpdv8

    hpdv8 Private E-2

    forgot to attach..
     

    Attached Files:

  11. thisisu

    thisisu Malware Consultant

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Did you remove TDSS File System using TDSSKiller?
    If not, please do this now.

    I do not think this is necessary but you can if you want.

    You're welcome :cool
     
  12. hpdv8

    hpdv8 Private E-2

    Sorry on that, no notice of "TDSS File System" ever came up.. What is that and how do I delete it?
     
  13. thisisu

    thisisu Malware Consultant

    I just wanted to make sure it was gone since it was in your in first TDSSKiller log (it's malicious). I can verify it's gone if you rescan with TDSSKiller with the "Detect TDLFS file system" option checked, and then upload the latest log here.
     
  14. hpdv8

    hpdv8 Private E-2

    Nice save! I almost messed this up.. Sure enough you were right. I deleted the TDLFS File System, and also saw that TDSSKille found 12 other files and quarantined them.

    I've attached the latest log file...
     

    Attached Files:

  15. thisisu

    thisisu Malware Consultant

    Good job :)

    Your logs are clean now. Surf safely!
     
  16. hpdv8

    hpdv8 Private E-2

    Thank again for all your help. And for being so quick with it too today.
    Is there a paypal address I could contribute to?
     
  17. thisisu

    thisisu Malware Consultant

    You're welcome.

    No there is not a paypal address to contribute to. Just tell your friends about MajorGeeks :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds