DOS/Alureon.A but unable to run tdsskiller (Kaspersky)

Discussion in 'Malware Help (A Specialist Will Reply)' started by FrostBlade, Mar 14, 2013.

  1. FrostBlade

    FrostBlade Private E-2

    I believe it was last Saturday [March 9, 2013] when my computer shut down and started causing me issues. Subsequent restarts would lead to a hard crash/BSOD. My computer had been off for about two weeks, and I downloaded updates to AV [McAfee] and Windows. It was shortly after updating that my computer first shut itself down. I decided to do a clean install of windows and re-format the Hard Drive in the process in order to start fresh, but apparently I have a stubborn one.

    [Note: after re-install, AV software is Symantec Endpoint Protection.]

    While downloading updates to Windows after the re-install, Windows malicious software removal tool identified the culprit as DOS/Alureon.A, and subsequent searches from the software in the R&R seem to back this up [specifically: HitmanPro identified something similar.]

    So I went through the R&R, and the issue comes with tdsskiller.exe [the Kaspersky program]. According to How to Remove Trojan:DOS/Alureon.A the integral process to removing this piece of malware apepars to be the ability to run tdsskiller. The problem is that whenever I run tdsskiller, my computer hard crashes to a BSOD and it does not complete the process. tdsskiller appears to be installed correctly and looks like it is running properly. I am able to start the scan, as directed/demonstrated in this thread: Re: TDSSkiller - How to run and the crash occurs just as the scan nears completion and right before you would expect to see the results. I checked and was unable to find a logfile for the scan. This is where I checked for the logfile: "Now go to the root of your C: drive and find the TDSSKiller log(s)."

    I tried to run tdsskiller in both normal [twice] and safe mode [once] and the end result was a crash every time.

    I am attaching the logfiles I have according to the R&R so hopefully someone can tell me where I am making a mistake. There are only 4 logfiles, due to tdsskiller not completing/creating a logfile.

    Thanks in advance for your help.
     

    Attached Files:

  2. FrostBlade

    FrostBlade Private E-2

    Hello FrostBlade!

    Welcome to MajorGeeks.com! Let me see if I can help you out.

    I understand you had been working on this for some time, and had to run off to work when you posted. If you follow the same link you did earlier (under Downloading Tools on this page) to tdsskiller.exe again, it will--for an unknown reason--download a slightly different version of tdsskiller with the same logo and different colors. The important thing here, is that this one works through to the end, and you will be able to "Cure" the problematic files that are causing you so much trouble. Additionally, you will get a logfile from tdsskiller that I am willing to bet looks exactly like the one I have attached. [Note: One file is from before restart, and one is from after.]

    If you pick up the R&R process from after the tdsskiller step, Hitman--which you indicated also recognized the Alureon.A file, will show the file to be gone. Finishing with MGTools will net you a logfile zip that looks exactly like the MGlog I have attached.

    I suspect that if you try to run windows malicious software tool, it will show that you have now removed the pesky files that caused you so much misery.

    -FrostBlade
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I don't understand the second message you posted. Why put this information in there that makes it look like some one was answering you in the forum? Did you have another thread some where that go incorrectly merged in here?

    Are you still having a problem? your second Hitman log looks clean? That is is looks like you must have allowed it to fix your bootkit problem?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds