Alureon.k XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by asandos, Feb 18, 2013.

  1. asandos

    asandos Private E-2

    Hello,

    I am able to boot into safe mode and complete all of the requested tasks, but I am still not able to safely boot into normal mode. When I do, I receive many pop up windows that say : "Windows - Read Error" - "Excpetion Processing Message 0xc0000029 Parameters 0x7c800023 0x0000000be 0x7c800784 0x7c8002e1" and "System message - Error Seek" - "The drive cannot locate a specific area or track on the disk. The system cannot find the drive specified. Storage to process this request is not available."
    Also, start menu and programs is all empty. There is a shortcut for a batch file called system repair on the desktop, along with all of the programs and logs that I put there while in safe mode.

    Before I went to your site, I ran Windows Defender Offline, and this gave me what I believe to be the name of the virus.

    I work for a corporate office and this was a director's pc, so I'm not sure what he was doing before it started acting like this. Also, I really just need to get the contents safely off, we have upgraded him to a Win 7 machine, we just need to recover some of his documents.

    Win XP - 32 bit

    Thank you for any help you can provide.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running RogueKiller.
     
  3. asandos

    asandos Private E-2

    Thank you
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKLM\[...]\Run : gYGLCRwuyRFWW.exe (C:\Documents and Settings\All Users\Application Data\gYGLCRwuyRFWW.exe) [-] -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n) [-] -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n) [-] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now click the Files/folders tab and locate these detections:


    • [ZeroAccess][FILE] n : C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n [-] --> FOUND
      [ZeroAccess][FILE] n : C:\RECYCLER\S-1-5-21-3423052178-432643065-2617760988-1287\$ff24043d55f85ce9a20a8337d9b4b888\n [-] --> FOUND
      [ZeroAccess][FILE] @ : C:\WINDOWS\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@ [-] --> FOUND
      [ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\@ [-] --> FOUND
      [ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-21-3423052178-432643065-2617760988-1287\$ff24043d55f85ce9a20a8337d9b4b888\@ [-] --> FOUND
      [ZeroAccess][FOLDER] U : C:\WINDOWS\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-21-3423052178-432643065-2617760988-1287\$ff24043d55f85ce9a20a8337d9b4b888\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\WINDOWS\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-21-3423052178-432643065-2617760988-1287\$ff24043d55f85ce9a20a8337d9b4b888\L --> FOUND
      [ZeroAccess][FILE] Desktop.ini : C:\WINDOWS\Assembly\GAC\Desktop.ini [-] --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now run Hitman and have it delete this:
    C:\Documents and Settings\All Users\Application Data\gYGLCRwuyRFWW.exe

    Reboot and re-scan with both RogueKiller and Hitman and attach both of those new logs as well.
     
  5. asandos

    asandos Private E-2

    There does seem to be quite a bit of stuff relating to "Disable task manager" and this is one of the many things that is disabled - I can't access it at all - should I worry about that?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Hitman and have it fix those two Task manager items. Tell me how things are running.
     
  7. asandos

    asandos Private E-2

    I took care of the task managers stuff, but still had things referring to the system repair on my desktop and in my start menu, but I was able to track it all down and clear it out, and everything seems to be ok now.

    Thank you so very, very much for your assistance!!!

    Have a great day!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds