emachine trojan:dos/alureon.j

Discussion in 'Malware Help (A Specialist Will Reply)' started by nycountrygirl, May 25, 2013.

  1. nycountrygirl

    nycountrygirl Private E-2

    Hi, My Name is Alice.

    My sister in law called and complained slow computer, redirecting and intermitten internet access. I tried to restore her Emachine ET1331G runing windows home premium 64bit, using the Emachine console, but got " Hard Drive configuration not set to factory " So Ordered the disc's from Acer.

    Once I got the discs, I did a complete install back to factory setting. All went well till I added Microsoft Security Essentials. On first run it came back with: Trojan:Dos/Alureon.J at Boot:\\.\physicaldrive0\partition0 (type 27)

    So, becasue I could not get to safe mode or use any of the tools provided by Emachine. I did a "dban Nuke and destroy" then I installed windows 7 back onto the computer. For a long time this computer could not get onto the internet, so I ran Windows Defender offline x64bit and I also ran Kaspersky's tdskiller offline. Defender found nothing but tdskiller found 13 files that it put in quarantine. Well, because I could not access internet still, once these files were in there, I did another reinstall. Ran Defender and nothing was found. Installed Security Essentials and once again it was found. (but at least I am on the internet)

    Believe I read everything you requested, and believe I did everything you wanted me to in the order you requested. No Antivirus is installed a this point, as it was blocking some of the programs you needed me to run. First Forum ever, hope I attached the items you needed!!

    Computer: Emachine ET1331G Windows 7 home Premium 64 bit version AMD Athlon(tm) II x2 250U Processor 1.60 GHz 4.00 GB (3.75 GB usable) ram. Trojan is Trojan:Dos/Alureon.J at Boot:\\.\physicaldrive0\partition0 (type 27)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Actually you did not attach anything? Try again. Watch for error messages in the manage attachments window. They are not always very obvious.
     
  3. nycountrygirl

    nycountrygirl Private E-2

    Sorry about that, thought that I just had to list them, didn't see the upload button. Hope this is better.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm no seeing an Alureon infection. Let's make sure it is not something stuck in System Restore. Disable System Restore and then reboot your PC. Do not reenable System Restore yet.


    Now please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  5. nycountrygirl

    nycountrygirl Private E-2

    Hi there, ran the scan as requested and the system restore is still off. Now if I can load the file correctly.. lol.. and by the way.. thanks a bunch for the help.. I am truly at a lose here..
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This log looks fine too. Run a full scan with Microsoft Security Essentials now and tell me if it still finds a problem.
     
  7. nycountrygirl

    nycountrygirl Private E-2

    Internet explorer would not let me download it. Is something we changed to work on the computer blocking it?

    Anyways, used my thumb drive and installed it and the internet allowed updates. and I watched as the scan was working.

    And yes it showed up again. And the log thing that is under the scanner that shows the files that are being scanned, said \\.\physicaldrive0 something-or-other... was moving to fast while I was trying to read... lol

    Attaching a screenshot
     

    Attached Files:

  8. nycountrygirl

    nycountrygirl Private E-2

    chaslang,

    Not sure if this is important or not... but I did 2 full system scans with microsoft security essentials .. before she told me she had the computer 6 years.. anyways the scans did not show up anything. I did the restore because she had the computer so long, and because she was having problems.

    This problem didn't show up until after I used the disc's bought from acer.. this will show you how little I know.. but could this trojan be written in the disc's I received? Would they show up on all the tests you had me run? Curious minds...want to know..
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is possible that it is a false detection of how Acer partition and formats the disks. Let me take a look thru the logs again. It may be worth a try fixing the MBR but that would not fix a partition infection if there is one.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Afer reviewing the logs again, I still see no signs of Alureon. I think you have a false detection from MSE. I think they are falsely detecting Acer's special MBR. I would uninstall MSE and try using one of the below instead.​
     
  11. nycountrygirl

    nycountrygirl Private E-2

    Because She cannot use the partitioned section of the disc for a system restore,( Harddrive configuration not set to factory ) is what I get when trying to use it.... Is there a way to just delete all the partitions and reformat the entire drive? Would that get rid of the false negative?

    I will try a different antivirus, but I was shutting it off for the night... so right now the computer is doing 103 updates.. lol... may take awhile before I can use the computer again.
     
  12. nycountrygirl

    nycountrygirl Private E-2

    Good Morning once again,

    Did not realize that I had one more symptom.. but when I was installing Acer disk, kept getting an error when inserting language disk.

    Anyways, used a disk partitioning program and deleted the boot and resource partitions.. the program allowed me to rebuild boot with their records within the program.

    So... many thanks to you for donating your Memorial Day weekend to helping!!

    We are fixed!! The error while loading language disk is now gone.. and also the trojan warning.. The computer is running Great. Microsoft Security Essentials is back on and finds nothing wrong in the drive.

    Again, Thank you for all your help!! You are a Saint in my book!! :major
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you got it all fixed up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds