Solved Trojan:DOS/Alureon.A

QCumber20

New member
Local time
2:18 PM
Messages
22
Location
Reykjavík
I've had this incredibly annoying infection for the last few weeks. I've done some searching online and don't get many clear answers about this one. It got to the point that i formatted my hdd, which was due anyway, but after a fresh install of Win 7 i still get prompts from MSE.

I've gathered that it's a MBR infection, which would explain it not being removed during formatting but I haven't the slightest clue how to repair one of those.
 

My Computer

OS
Windows 7 Home Premium 64bit

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
Hi,

Did you do a full reformat (deleting partitions as well)?
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 8300
OS
Windows 7 Ultimate x64
CPU
Intel Core i&-2600 3.40 Ghz
Motherboard
Dell 0Y2MRG
Memory
12GB DDR3
Graphics Card(s)
AMD Radeon HD 6600
Sound Card
Sound Blaster X-Fi Titanium
Monitor(s) Displays
24" Dell and 22" Dell
Screen Resolution
1920x1080
Hard Drives
2.0TB Seagate
Keyboard
Dell OEM
Mouse
Dell OEM
Try running the TDSSKiller.exe from Kaspersky. This tool can spot and remove rootkit such as Alureon but cannot be sure if your computer is clean though. Save it to your desktop. Double-click on TDSSKiller.exe to run the tool for known TDSS variants. Windows 7 users right-click and select Run As Administrator. Make sure you click on the link for TDSSKiller.exe where it says; 'Execute the file TDSSKiller.exe.'

How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)?

And if you have MBAM already run that too. Make sure it has the latest updates and run in regular mode.

Malwarebytes Anti-Malware - Free software downloads and software reviews - CNET Download.com
 

My Computer

Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Home Premium 64bit
CPU
AMD Phenom II X4 965 3.4Ghz
Motherboard
Asus M4A89GTD PRO/USB3
Memory
Corsair XMS3 4GB DDR3 PC3-12800C9 1600MHz
Graphics Card(s)
Gigabyte GeForce GTX 460 1GB
Sound Card
High Definition 7.1 Onboard Sound Card
Monitor(s) Displays
Benq XL2410T 24" TRUE 120Hz 3D Widescreen LED Monitor
Hard Drives
Seagate Barracuda 1TB SATA-II 16MB Cache
PSU
Corsair CX 600W
Case
Antec 300 case
Cooling
2 TriCool rear and top, Thermaltake Frio
Keyboard
Logitech Wave keyboard
Mouse
HP USB Mouse
Internet Speed
7-9Mbps
Other Info
KIS 11.0.2.556 (a,b,d), Malwarebytes Pro, Office 2010 Professional Plus, Acronis True Image Home 2011
When I first googled the issue i found a thread on Majorgeeks, as i recall. Anyway the thread solved the issue by running TDSKiller and MBAM, both of wich i have and have already run. MBAM found nothing and TDSKiller found the malware and was supposed to "complete cure after reboot" but after more than one try the rootkit still comes up after reboot.

I've already formatted the hdd, I'm thinking of just doing the "Clean All" procedure to save me the trouble, if you still think that's a good idea
 

My Computer

OS
Windows 7 Home Premium 64bit
Yes, that's the best idea! ;)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Just one last thing.

The drive in question is the OS partition and boot drive. Neither of the Dos prompt options allows me to "clean all" because I've already booted up Windows 7

How do i go about "cleaning all" on a Boot drive?
 

My Computer

OS
Windows 7 Home Premium 64bit
In order to clean the Windows drive, you must boot from the installation DVD or repair disc, and run the command from there. Boot up the Windows DVD, and select "Repair my computer". Open a command prompt from that screen.
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
The Clean All function seems to have done the trick. Many thanks!
 

My Computer

OS
Windows 7 Home Premium 64bit
No problems, glad to hear it!
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
Back
Top