Windows 7 BSOD after removing Alureon Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by alexsirb, Apr 24, 2014.

  1. alexsirb

    alexsirb Private E-2

    I got the BSOD after I removed Trojan Alureon with Windows Defender Offline. I used the Farbar Recovery Scan Tool and this is what I got. Could anybody please help me with the next step? Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot into normal Windows.
     
  3. alexsirb

    alexsirb Private E-2

    Thanks for getting back so quickly. Here is the Fixlog file.

    Is there anything else that I need to do to make sure that this virus is gone for good?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not tell me if you can boot up now.
     
  5. alexsirb

    alexsirb Private E-2

    Sorry. I forgot. Yes I can boot.
     
  6. alexsirb

    alexsirb Private E-2

    I just want to make sure that if I run a virus scan and find the virus there, that I do not get the blue screen again.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions tell you to run the scans but not fix anything, just attach the scan results.
     
  8. alexsirb

    alexsirb Private E-2

    I have run the scan and this is the fixlog file I got. I can boot the system. Is there another step that I have to do? (if you do not see the fixlog file, it should be in the thread above).
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. alexsirb

    alexsirb Private E-2

    Thank you! I ran the scans and here are the logs. I got red flags on Rogue Killer and Hitman.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it fix what it found. Then after a reboot, tell me what issues remain, if any.
     
  12. alexsirb

    alexsirb Private E-2

    Hitman shows everything good after rerun and boot. Should I run RogueKiller and fix those issues, too? Thank you!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Those are not problems. They are normal. Your logs are clean. The only thing you need to do is update Sun Java

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java(TM) 6 Update 17

    Now install the current version of Sun Java from:

    Then if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds