BleepingComputer.com: Infected with Alureon (perhaps even more)

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Infected with Alureon (perhaps even more)

#1 User is offline   RDC123 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 16-November 10

Posted 16 November 2010 - 10:49 PM

Good evening!

I was asked to have a look at a friends machine (a Dell Dimension E520 running Windows XP) to remedy what sounded like a fairly routine spyware/malware related issue. Having cleaned many machines over the course of the past few years, I rather confidently took the machine to work on it. I had no idea what I was getting myself into, lol! I've had the machine for a couple days now, and I have run countless scans, using several different tools (Malwarebytes, Spybot, SFC, Rootrepeal, HijackThis, to name a few), and have gotten the machine to the point where nothing is detected. However, there are several remaining symptoms that have left me pulling out my hair trying to remedy. SVCHOST errors, inability to do Windows updates, and things of that nature. It seems that when I try to do anything to get around the OS, like boot with Windows XP Prof. CD, or ERD Commander, the machine bluescreens. In a last ditch effort to manipulate some system files based on articles I've read, I tried attaching the machines hard drive to another machine (mine, Thinkpad T400 running Windows 7) via a USB/SATA adapter, and that's when my Microsoft Security Essentials immediately detected the Alureon when the drive mounted. If this were my machine, I would have just reloaded it by now, but since it belongs to fairly PC illiterate person, I'd rather not have to reload if at all possible, since they have no idea where any of the media is for the software they have installed, and I'd rather not have to 'own' that whole ordeal.

Please forgive the vague and anecdotal nature of the problem description, as I've been over the machine such that I can't even remember all I've done to it. Given what I've uncovered tonight, I'm looking for guidance, since I am clearly not getting anywhere on my own.

Please advise.

Thanks in advance.
Rod

#2 User is offline   Budapest 

  • Bleepin' Cynic
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 22,235
  • Joined: 11-November 06
  • Gender:Male

Posted 16 November 2010 - 10:57 PM

http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 User is offline   RDC123 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 16-November 10

Posted 16 November 2010 - 11:32 PM

Budapest,

Thanks for that link! Ironically, I was on the trail of TDSSKILLER earlier this evening, but it seems that no matter where tried to download it from (Kaspersky included) when extracting it from the ZIP, there was corruption, and the .exe wouldn't extract properly, presenting the following error: ! C:\Users\RDC123\Desktop\Virus Tools\tdsskiller.zip: CRC failed in TDSSKiller.exe. The file is corrupt. At first, I thought that it might have been machine specific, but no matter what machine I tried to extract it on, I was met with the same error. Moments ago, after posting my topic, I came across a link to TDSSKILLER.exe in another thread that points directly to a 'good' copy of the exe, versus the ZIP, and I am running it now, and sure enough, it detected! AND it looks like it let me cure it!! Following the reboot, I immediately tried a windows update, and was able to get them to install. I'll continue to follow the advice in the link you provided, to ensure any remnants are cleaned up.

Thank you kindly, it appears I am much better off now, than before! With any luck, this will be the last you hear from me. :)

#4 User is offline   Budapest 

  • Bleepin' Cynic
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 22,235
  • Joined: 11-November 06
  • Gender:Male

Posted 16 November 2010 - 11:34 PM

:thumbup2:
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users