1. mountinrich

    mountinrich Private E-2

    I've got a laptop running Win 7. 2 days ago it got a Trojan. AVG will not run, AdAware will not run, Firefox and Chrome will not run, even Adobe Reader will not open.

    I did succeed in running Windows Defender for a full scan. After 4.5 hours, it told me the computer has DOS/Alureion.A and Win32/Alureon.FK Trojans on it.

    I tried to load SuperAnitSpyware and Malwarebytes. I also tried MGtools, tdsskiller and RootRepeal. For each one, I got a Program Compatibility popup, which asks if the program loaded ok. If I hit either Yes or No, it goes away, but the program will never try to load again. Is the trojan causing a fault in the Compatability module?

    I have also tried SOS and Malwarebytes in the portable form, running from a flash drive. This has the same results. I even tried to install Revo Uninstaller, both regular and portable versions with the same result.

    I have backed up all of my documents, photos, and music onto an external HD, and ran malwarebytes and AVG on those files, which all came out clean.

    Is there anything else I can try, or will I need to do a full recovery on this thing?
     
  2. mountinrich

    mountinrich Private E-2

    Is there a way I could get at this from Linux? Is there a malware or rootkit scanner that I could load onto a flash drive then boot the computer with my Puppy Linux cd and run it?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To repair broken EXE file associations, download the correct registry fix below.

    EXE FILE FIX WIN_7

    1. You can use Right-click and Save as ( or Save Target As ) option in your browser to download the patch.
    2. Save the patch file directly to your Desktop folder.
    3. Right-click the REG file and choose Merge. Alternately, you can open the Registry Editor and then using the Import option from the File menu, to merge the REG file contents.
    4. Note that you need to be an administrator to apply these fixes.

    Now try working your way through the R&R:

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your Win 7 boot CD handy?
     
  5. mountinrich

    mountinrich Private E-2

    Been a few days since I could get at this. Unfortunately, the .exe fix didn't change anything. I've even tried renaming things, but just get the compatibility popup, then the program will not run. I have ordered a System Restore disk from Acer, but it hasn't arrived yet.

    If I have to do a rebuild, do I need to wipe the hidden partitions as well? I'm guessing they are infected as well.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The system restore disk won't do it. You should purchase a windows 7 recovery disk. It has a price tag of $9.75.

    Now that you have the DVD, you need to boot from it to access the Windows 7 System Recovery Environment. You can read details about this in the below link:

    http://www.bleepingcomputer.com/tutorials/tutorial161.html

    Once you have gotten to the command prompt, you need to run the below command

    bootrec.exe /fixmbr


    Then you will reboot normally back to Windows and attach a log from MBRcheck
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds