Need help removing Trojan:Dos/Alureon.A

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rrwg37s, Dec 10, 2011.

  1. rrwg37s

    rrwg37s Private E-2

    I have Windows 7 64-bit on a Dell Inspiron 1545. My anti-virus program is Microsoft Security Essentials and I'm using Superantispyware Free Edition.

    Yesterday MSE detected Trojan:DOS/Alureon.A, said it removed it, but also got a pop-up from MSE "Download required" "Some threats could not be removed... telling me I needed to download Standalone System Sweeper. I downloaded it from another computer onto DVD, booted up from DVD, ran the tool, but it didn't even find the Trojan. Ran it a second time, same thing.

    These notifications are continuing. Need to get rid of this thing.

    I have downloaded and run TDSSkiller, but it doesn't appear to have taken care of the problem. Also ran MBR check and followed the steps in the Malware Removal Guide (READ AND RUN Me First, which I found at another thread) - except I couldn't get ComboFix to install completely.

    It looks like the Trojan is still there.

    What's next?
     

    Attached Files:

  2. rrwg37s

    rrwg37s Private E-2

    Here are the MG logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have a Win7 boot disc?

    Why did you not allow TDSSKiller to try to fix what it found?

    Please attach a screen shot of your disc management partitions. I think one of them is a faked partition and we may need to remove it.
     
  4. rrwg37s

    rrwg37s Private E-2

    I have the Reinstallation DVD that came with my Dell.

    When I ran TDSSKiller, it only detected "suspicious" objects. The "TDSSKiller How to Run" instructions said to skip suspicious objects. It did not detect any malicious objects, so there was no option to "cure" or "delete". (I actually ran it twice and quarantined some objects the first time, before I realized the instructions said to skip - I posted the second log, where I skipped, not the first).

    I have attached a Word doc with the screen shot of the partitions. Looks normal, but I have a folder in the root directory that I don't recognize - screen shot of partial contents of 32788r22fwjfw is on page 2.
     
  5. rrwg37s

    rrwg37s Private E-2

    Screenshot attachments
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK, the partitions appear to all be legit. Boot to the bios and change the boot order to CD/DVD as first boot device. Get into the Recovery Environment and choose the Command prompt option. Once in the command prompt, type this:
    Bootrec.exe /fixmbr

    Exit out and reboot to normal mode and then re-run MBRCheck and attach the new log.
     
  7. rrwg37s

    rrwg37s Private E-2

    I'm afraid I cannot restart Windows.

    I was able to get into Recovery Environment and Command Prompt, typed Bootrec.exe/fixmbr. It said operation successful, then I attempted to re-start, a blue screen flashed for a second, then got the black screen (windows error recovery) telling me I need to run startup repair, I switched to start normally, but I can't get it to start. I tried the startup repair, but it couldn't repair it - 4 attempts, nothing.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot back into the Command prompt and try:
    bootrec /FixBoot

    Do note the space after bootrec and /
     
  9. rrwg37s

    rrwg37s Private E-2

    Still won't start up.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to download: gparted-live-0.10.0-3.iso (115.1 MB)

    Create a bootable CD, from the ISO images. You can use ImgBurn to do this.

    Now boot off of the newly created Gparted CD.

    Make the partition is active with the Disk Management.

    Right click and manage flags, and double check it is set to bootable in GParted.
     
  11. rrwg37s

    rrwg37s Private E-2

    OK. I now have 4 partitions: DellUtility (flag is currently set to diag), Recovery (flag is currently set to boot), OS, & unallocated. Which one should be set to bootable?
     
  12. rrwg37s

    rrwg37s Private E-2

    I set OS to boot and now I'm seeing "BOOTMGR is missing Press Ctrl+Alt+Del to restart".

    This seems to be getting further and further away from the original problem. What am I doing wrong?
     
  13. rrwg37s

    rrwg37s Private E-2

    Somehow, I was able to restart windows after re booting from the reinstallation DVD. Ran MBRcheck again and attached log.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBRCheck log is clean. What issues are you still having?
     
  15. rrwg37s

    rrwg37s Private E-2

    Everything seems to be running correctly. It appears the malware has been removed.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds