Possible Trojan:DOS/Alureon.A... or not

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChrisHicks23, Aug 10, 2012.

  1. ChrisHicks23

    ChrisHicks23 Private E-2

    So, I have what appears to be an Allureon.A infection (as diagnosed by MSE) but experience seems pretty atypical.

    My Windows 7 (64 bit) PC boots just fine, normal mode, safe mode and otherwise, but with the exception of MSE and a handfull of programs associated with windows (like windows explorer, regedit, etc) I cannot open any other program (.exe, .com, .scr, etc) The program appears to start with *32 after the name in the taskmanager), but then winks out again.

    I have tried renaming files to something innocuous, something that seems to be allowed to run. No luck.
    No TDSSkiller.
    No RKill (RKill, might be running - get the black window and a brief appearance in the TM for a few seconds, but nothing else)
    No matter how I rename it or tweak the extension.

    Micorsoft Security Essentials detects "Trojan:DOS/Alureon.A" but doesn't seem to be able to remove it. Booting and scanning with Windows Defender Offline finds nothing.

    Other than that, nothing overtly suspicious. No browser redirects or pop ups, since i can't open a browser. Of course, I have disconnected the ethernet anyway, just to be safe.

    CHKDSK does show some errors, which would seem to jibe with Alureon.

    The only other program I have been able to run is FRST64. The txt file from that is attached below.

    I have read about people having some luck deleting entries from the registry, but that's not the kind of thing I'd want to do unguided.

    Anyhow, I'd appreciate any help. Thanks in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Now follow these procedures:

    I want you to run TDSSKiller so refer to the below for how to do so. (DO NOT just quit after running TDSSKiller and MBRCheck, there is MUCH more to do, scroll further down and follow the Read and Run Me First Malware removal procedures link.)

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.




    Now do not stop, please continue on with the below instructions too! :)

    v
    V
    V
    V
    READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  3. ChrisHicks23

    ChrisHicks23 Private E-2

    Hey, just wanted to post a follow up. Kaspersky has a free, downloadable iso that creates a bootable scan disk. It allows me to get about the nastier parts of the infection and remove them.

    http://support.kaspersky.com/viruses/rescuedisk?level=2

    Slowly on the road to recovery!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :) Yes we know about the rescue disk. So are you saying you no longer require my assistance?
     
  5. ChrisHicks23

    ChrisHicks23 Private E-2

    Still running a bit slow - but I am up and running. Now that I can run my other Antivirus, I should be able to handle it from here. Just wanted to post about the rescue disk in case any else has a similar problem.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, that's fine. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds