Windows 7 won't boot after removal of Alureon

Page 1 of 2 12 LastLast

  1. Posts : 7
    Windows 7 Home Premium x64
       #1

    Windows 7 won't boot after removal of Alureon


    I removed the Alureon Virus following some steps that were given to me via MS Security Essentials. Now I am getting a BSOD and cant get into anything except repair your system.

    I have ran frst64.exe because of some other threads that I read. I am not sure what to do now. I am attaching the log from running frst64.exe.

    Thanks for any help.
    Windows 7 won't boot after removal of Alureon Attached Files
      My Computer


  2. Posts : 2,470
    Windows 7 Home Premium
       #2

    RustyBrotherton,

    Please do the following:

    Open notepad (Start > All Programs > Accessories > Notepad)
    Copy the entire contents of the quote box below (Do not copy the word 'Quote');
    Save it on the pendrive that has FRST64 and name it: fixlist.txt

    start
    HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\n. ATTENTION! ====> ZeroAccess
    AppInit_DLLs: [0 ] ()
    C:\Users\Amy\Application Data\eufihagb
    C:\Users\Amy\AppData\Roaming\eufihagb
    TDL4: custom:26000022 <===== ATTENTION!
    end
    WARNING: This script is written specifically for RustyBrotherton, and, for use on this computer.
    Running this on another computer may cause damage to the Operating System!!

    Now, please enter System Recovery Options and select the Command Prompt as done before.
    Run FRST64, and press the Fix button, just once, and wait.

    FRST reboots the computer.

    When done, the tool creates a report on the pendrive called: Fixlog.txt
    Please post Fixlog.txt in your reply.

    Post back on whether you can boot normally to Windows.
      My Computer


  3. Posts : 7
    Windows 7 Home Premium x64
    Thread Starter
       #3

    I just booted into Windows normally!!!

    Here is the log.

    You guys are seriously amazing!!
    Windows 7 won't boot after removal of Alureon Attached Files
      My Computer


  4. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #4

    RustyBrotherton

    Once you're up and running . I recommend removing McAfee

    McAfee Removal Tool MCPR.exe

    Drag the MCPR.exe file from your Downloads folder to your Desktop folder

    Right-click MCPR.exe, and select Run as administrator.

    If you get a User Access Control window click on the Yes button

    At the End User License Agreement (EULA) dialog box, click Next button to accept the agreement.
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #5

    Please hold off on McAfee until we get done removing the malware.

    Will be back shortly...
      My Computer


  6. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #6

    Yes cottonball that is why I said once you're up in running . Meaning when the virus is removed .
      My Computer


  7. Posts : 7
    Windows 7 Home Premium x64
    Thread Starter
       #7

    I just ran tdsskiller.exe and it said no threats found. Additionally I loaded MS Security Essentials and it found no threats as well.

    I might have been to quick but I had already ran the MCPR.exe
      My Computer


  8. Posts : 2,470
    Windows 7 Home Premium
       #8

    We are switching to the Desktop...no pendrive.
    Also, TDSSKiller produced a report. Please post it in your reply.


    Please go to the: Farbar Recovery Scan Tool Download
    Select the 64-bit version.
    Save it to your Desktop.
    You will use it shortly.


    Open Notepad (Start > All Programs > Accessories > Notepad)
    Copy/paste all the contents of the quote box below to Notepad (do not copy the word 'Quote').
    Save it on the Desktop as: fixlist.txt
    start
    DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
    end
    Run FRST64 again (from the Desktop), but this time press the Fix button just once, and wait.
    When done, the tool makes a log on the Desktop.
    Please post Fixlog.txt in your reply.


    Since the following steps involve editing the Registry, please create new restore point before proceeding.
    System Restore Point - Create
    Select: Option Two


    Now, please download the ESET ServiceRepair:
    http://kb.eset.com/library/ESET/KB%2...icesRepair.exe
    Save to the Desktop.
    Double-click and run the downloaded file.

    When the program runs, a prompt appears asking if you want to proceed.
    Click: Yes
    When the Services routine is Completed, you are asked to Reboot.
    Click Yes to allow the reboot.

    The tool creates a folder named CC Support on the Desktop.
    Please provide the CC Support\Logs\SvcRepair.txt in your reply.


    Last, please take action Downloading Farbar Service Scanner
    Save to the Desktop
    Make sure the following options are checked:

    Internet Services
    Windows Firewall
    System Restore
    Security Center
    Windows Update
    Windows Defender

    Press: Scan

    FSS creates a log, FSS.txt, on the Desktop.
    Please provide the FSS.txt in your reply.


    Need for you to attach 4 reports:
    TDSSKiller
    Fixlog.txt from FRST64
    SvcRepair.txt
    FSS.txt
      My Computer


  9. Posts : 7
    Windows 7 Home Premium x64
    Thread Starter
       #9
      My Computer


  10. Posts : 2,470
    Windows 7 Home Premium
       #10

    RustyBrotherton,

    There is still some more work to do, but the mean malwre is out of the picture.

    VistaKing, in California, will run you through the routine of geting rid of McAfee.


    In Illinois, it is 12:45AM, past my night-night time.

    Will se ya later, probably in the afternoon!
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:23.
Find Us