Alureon removed now Windows 7 won't boot

Discussion in 'Malware Help (A Specialist Will Reply)' started by dmlester, Apr 23, 2012.

  1. dmlester

    dmlester Private E-2

    Hello, :wave

    I removed a MBR infection of Alureon and now the system just gives me a bsod even trying safe mode. Boot up repairs, system restore, etc. all fail to correct the issue. The bsod error is STOP: 0x0000007B (0xFFFFF880009A9928, 0xFFFFFFFFC000000D, 0X0000000000000000, 0X0000000000000000)
    Also, please find my scan file attached. For future reference, is there a way to remove Alureon without killing the boot up? This is the second time I've removed Alureon and had this happen. Thank you in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Come to this forum and run our cleaning procedure and attach the requested logs to allow a malware removal expert guide you in the removal process. These infections constantly change and there are no set procedures that will always work. Typically some form of manual intervention is always required and the steps are based upon the form of the infection that you have. As it it evolves ( sometimes many times in a day ), so do the cleaning procedures. The infection is designed to break your PC when attempts at removal are performed especially if incorrect steps are taken or the order of the steps are not correct.

    Download this >> View attachment fixlist.txt

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows if possible. Did this help?
     
  3. dmlester

    dmlester Private E-2

    :) We have Windows! Thank you! Here's the file.
     

    Attached Files:

  4. dmlester

    dmlester Private E-2

    I apologize for replying to my own post, but I thought it would be worth noting that not all programs are showing under the "All Programs" menu and the desktop is black despite applying a theme.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. dmlester

    dmlester Private E-2

    :) Things are looking better. Hidden stuff is now visable. I've attached the logs. The system feels clean, so hopefully we're close. Logs attached.
    Note that Malwarebytes found nothing, therefore it did not produce a log.

    Thanks!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's make sure they all came back. I can see that many items ( like Start Menu, All Program...etc ) were moved to a temp folder.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did restore any more items?
     
  8. dmlester

    dmlester Private E-2

    Nothing additional. Thank you so much! Should I do anything further? (Aside from installing an antivirus and grabbing M$ updates.)
    :major
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds