WIN XP will not boot after cleaning DOS/Alureon.K

Discussion in 'Malware Help (A Specialist Will Reply)' started by bnelsonoak, Oct 16, 2012.

  1. bnelsonoak

    bnelsonoak Private E-2

    Ran a full scan and MSE found Trojan:DOS/Alureon.K and I let it clean it. It said to reboot to finish, but it appears to start loading Win XP but then goes to a black screen.

    Dell Optiplex 760 - Win XP Pro, Service Pack 3

    The initial problem was that the files showed as hidden and MSE showed WIN32/FakeSysdef and WIN32/Tibs.IT and said they were quarantined

    Files had also been hidden, but had not run unhide.exe before letting MSE do the full scan this morning.

    I ran Malwarebytes yesterday, but could not run in SafeMode as the computer would only boot to Windows as it ignored my pressing F8

    Sorry to say, but I do not have a bootable CD

    Would appreciate any help I can get.

    BN
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    You need to buy one or borrow one as you will need to get to the Recovery Console at a minimum to try and restore any system file or files that were deleted. You need to know what MSC deleted so that you can restore it. Another possibility is to run system restore from the recovery console. See >> http://forums.whatthetech.com/index.php?showtopic=105819
     
  3. bnelsonoak

    bnelsonoak Private E-2

    Good morning, and thank you for helping.

    I was able to get a Win XP Pro CD - Svc Pack 1 Version 2002. I also created a Recovery Console CD from your link, and tested it on another computer and it works.

    Wish I had found your site before this problem, but have now gone through your Malware Removal Guide and downloaded all the XP Tools mentioned.

    Please let me know the next step you would like me to take.

    BN
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use system restore to restore you computer and are you able to boot into Windows now? If yes, then you need to run the malware removal guide steps and attach the logs we need.
     
  5. bnelsonoak

    bnelsonoak Private E-2

    Chaslang - I didn't try the System Restore yesterday, because I wasn't sure I was suppose to. I tried today, but using the Recover CD & the Operating CD both several times when it got to Windows Loading it just returned: Stop Error 0x0000007B.

    I gave up and pulled the HD and replaced it and reloaded my original Acronis image from 2010. With the original HD it would just hang and wouldn't start the image restore process.

    After that, I did run the Removal/Cleaning tools and have attached the log files.

    Thank you for helping.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean but you may have a lot of updating to do since you reimaged with a two yr old image. For example you now have Java(TM) 6 Update 16 and the current version is about 7 update 5.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
     
    Last edited: Oct 22, 2012
  7. bnelsonoak

    bnelsonoak Private E-2

    Chaslang

    I've done all the updates, cleanup, and followed the How to Protect Yourself from Malware Guide. Even have a new image made, so for now I think I'm good to go.

    Thanks so much - BN
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds