Re-occuring Issues on format. Trojan suspected

Discussion in 'Malware Help (A Specialist Will Reply)' started by F4tal3rror, May 27, 2009.

  1. F4tal3rror

    F4tal3rror Private E-2

    Hello, i usually fix all my own virus/malware issues, usually using spybot search and destroy to run checks for malware, and immunise against websites, and abstaining from anti-viruses, manually removing issues (virus' where and whenever they arose. (rarely, due to safety procedures)

    However, I've had an issue very recently where i was receiving errors stating that a recycler was missing when attempting to browse any hard drive.
    I googled, and used Autorun Eater, which fixed this problem in a temporary measure, as the files in question were being recreated.
    I looked at my running processes, and didn't see anything out of the ordinary, didn't check my services or what not, and noticing the seriousness of the issue, i attempted to install kaspersky trial to help. I had to uninstall spybot search and destroy because of the 'compatibilty issues' between the two programs. After installing, kaspersky would not run, and i was unable to reinstall spybot search and destroy. Also, no major name applications would work, and usually whether the site it's self and or the update link/s could not be pinged from my machine.

    I thought this was very serious, and instead of using hijack this at all, i went straight for a format, before i'd even finished reinstalling drivers, the issue had replicated it's self.

    Obviously, even without running any programs from other drives, it is reinfecting my system drive, so i reformatted again, with all other hard drives disconnected.
    I currently have kaspersky installed and updated, am about to restart and then install spybot search and destroy.
    I am not prepared to format the other hard drives, as i have much data invested on them, and am wondering what advise people may have in preperation and in the act of attempting to cleanse them of any malicious program, as i am worried that as soon as i plug them back in, my system will be reinfected, and any running programs will be disabled through some method.
    I would install norton ghost and create a ghost image of my system disk, to revert to, should that occur, however, i have no hard drive i can trust to do that.
    What do you all think?
    Thanks in advance for your advice.
    F4tal3rror

    As i went to post on majorgeeks.com, i found myself logged out, then redirected to "http://xsaimex.mybrute.com" =/
    I've saved this in a .RTF and am going to restart then try again.
    The redirects are still occuring on your site, and i have to press esc to stop them. I probably should have installed firefox, noscript. I've currently only installed my motherboard drivers, kasperspy AV, and about to install spybot S&D.
     
  2. F4tal3rror

    F4tal3rror Private E-2

    I installed servicepack 3, plugged in the hard drives (hoping i'd be pretty right with kaspersky and having spybot S&D locking the registry.
    The issue maintained on all other drives except my system drive, due to being protected.
    I turned system restore off was doing a full scan with kaspersky, when i went i remembered to get the security update for sp3 as well as any other tidbits.
    Accidently installed windows search 4.0, which i find just annoying, didn't click the tickbox to not restart, thinking it was the other way around (tick here to restart now)
    There was a maliciousfile remover in the update, and it found trojan:win32 alureon!inf, which it apparently removed.
    When i restarted and have started another scan with kaspersky and thus far, it has been finding alureon!inf related files, and deleting them.
    I should be pretty right afterall.
    I had a look at the files themselves and the icon of one of them, and i know exactly where they came from :***.
    The same place i noticed a trojan (don't remember if it was the same one) came from before. *Grrr* A friend said he used a file from a p2p site, and so i did too, assuming it was safe, and instead of scanning it like i normally would, with jotti.org
    Advice: Don't trust files just because you'd think a friend would notice being infected with something. Scan everything suspicious yourself.
    Thanks anyway guys. My system looks clean now (hopefully)
    I should be right for the lan i have in a couple of days :D

    Edit: Also, about the direct that was occuring on your site (and only your site), it still occured, even with firefox and noscript until i installed servicepack 3, though i used a siteblocking addon for firefox in the mean time.
    I'd advise checking any and all adds your site runs, as it only seemed to be on this site, i'd suspect it might be hidden in an add someone has on your website.
     
    Last edited: May 27, 2009
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    As I have not seen any of these redirects and have not seen anyone else mention them, I have asked the owners to check out your post.

    I know you say you are not having anymore problems at this time but I would advise you to work thru the below two procedures. One to avoid autoruns issues and the other to help ward off issues with malware.

    Disabling AutoRuns

    How to Protect yourself from malware!
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Uh.... how about telling us where your getting the redirect so we can check it, after all, malware would never cause any redirects. /sarcasm off.
     
    Last edited: May 30, 2009
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes more than likely it is malware that is still in place that is causing the problem. Other people have had redirects like this and our cleaning procedure removed it for them. You probably have malware hooked into your browser or into Java.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds