Author Topic: MBR:Alureon-K [rtk] partion 3  (Read 12484 times)

0 Members and 1 Guest are viewing this topic.

s.grundy

  • Guest
MBR:Alureon-K [rtk] partion 3
« on: April 04, 2012, 07:18:01 PM »
I found I was infected with MBR:Alureon-K[RTK]  through Avast Antivirus.  It gave me the option of deleting it, but it but it didn't work.  I also used the program  aswMBR, because I read it in one of your forums.  It found the virus but I was afraid to use it to fix it as it warned me that it would change everything.  I did save the log though.   I have also used Malwarebyte Anti-Malware, but it didn't find it.

So far this virus hasn't really done much, at least that I know of, but I am afraid it will.  Can someone please help me.

S.Grundy
« Last Edit: April 04, 2012, 07:26:17 PM by s.grundy »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: MBR:Alureon-K [rtk] partion 3
« Reply #1 on: April 04, 2012, 07:25:25 PM »
Well avast is keeping it from spreading, but you will need help of a specialist to remove it completely.

This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #2 on: April 04, 2012, 11:42:46 PM »
Here are the logs you requested.

S.Grundy

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #3 on: April 04, 2012, 11:49:31 PM »
More logs!!!

S.Grundy

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #4 on: April 04, 2012, 11:51:23 PM »
Last log!!!  Sorry, but it said the files were to big to send all at once.

S.Grundy

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:Alureon-K [rtk] partion 3
« Reply #5 on: April 05, 2012, 12:13:46 AM »
While I look at OTL could you do the following

Go start > Run

Type in the following command and press enter

diskmgmt.msc

In the disc management that opens locate partition 3
Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS            2 MB offset 976769024

Right click the partition and select delete
Re-run aswMBR

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:Alureon-K [rtk] partion 3
« Reply #6 on: April 05, 2012, 12:17:28 AM »
OK the fix is easy

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    [2011/12/26 16:34:10 | 000,008,366 | -HS- | C] () -- C:\Users\Joe\AppData\Local\1ybu3or54qr570kjb4y
    [2011/12/26 16:34:10 | 000,008,366 | -HS- | C] () -- C:\ProgramData\1ybu3or54qr570kjb4y
    [2011/06/04 18:31:12 | 000,011,470 | -HS- | C] () -- C:\Users\Joe\AppData\Local\0vyjnrk111j80em8nn
    [2011/06/04 18:31:12 | 000,011,470 | -HS- | C] () -- C:\ProgramData\0vyjnrk111j80em8nn
    [2011/03/09 20:52:07 | 000,000,457 | ---- | C] () -- C:\Program Files\0309201119520762.bat
    [2011/03/09 20:48:45 | 000,000,453 | ---- | C] () -- C:\Program Files\0309201119484476.bat

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #7 on: April 05, 2012, 12:28:48 AM »
Do you still want me to use the diskmgmt.msc

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: MBR:Alureon-K [rtk] partion 3
« Reply #8 on: April 05, 2012, 12:33:01 AM »
quote essexboy
Quote
While I look at OTL could you do the following..............

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #9 on: April 05, 2012, 12:45:55 AM »
I tried the diskmgmt.msc command, but cannot find the line you want me to delete.  Sorry!!!

I'm not doing something right, because I don't see anywhere I can even see partion 3.  Help!!!
« Last Edit: April 05, 2012, 12:53:16 AM by s.grundy »

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #10 on: April 05, 2012, 12:58:57 AM »
Should I use the fix without the diskmgmt.msc command???


s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #11 on: April 05, 2012, 01:56:45 AM »
I ran the fix you wrote up although I never figured out the Disk Managment program, so I could not locate

partition 3,       and I could not delete
Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS            2 MB offset 976769024

The log that came up after the fix said that all the processes were killed successfully.
I also ran the OTL scan after the fix and I am attaching it as you requested. 

S.Grundy

« Last Edit: April 05, 2012, 03:17:50 AM by s.grundy »

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #12 on: April 05, 2012, 02:00:53 AM »
I also ran a scan with aswMBR to see if the virus was deleted.  According to the scan, the virus is still there.
I have attached it.  Anything else I can do.

Have to go for awhile.
« Last Edit: April 05, 2012, 03:06:48 AM by s.grundy »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: MBR:Alureon-K [rtk] partion 3
« Reply #13 on: April 05, 2012, 11:25:20 AM »
The mbr detection will still be there until you remove the bogus partition 3 using the Disk Managment function.

I ran the fix you wrote up although I never figured out the Disk Managment program, so I could not locate

partition 3,       and I could not delete
Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS            2 MB offset 976769024

The log that came up after the fix said that all the processes were killed successfully.
I also ran the OTL scan after the fix and I am attaching it as you requested. 
<snip>

So why couldn't you delete that partition 3, e.g. what errors did you get ?
Or is it that you don't know how to use the Disk Management function ?

If the latter then press the Windows Key+R together this opens up the Run window, type diskmgmt.msc and click OK. That will open up a window like my example image (click to expand), this shows you all of the Drives/Disks and Partitions you have.

Find the Disk 0, Partition 3 one that is only 2MB in size:
b]Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS            2 MB offset 976769024[/b]

Now right click on that Partition and you should see a list displayed, it may differ sightly from my example (I'm using windows XP), but should look very much the same. From that list select Delete.

Exercise extreme caution and select the correct partition Disk 0 - Partition 3 - 2MB in size or you could delete an important partition, with serious consequences.

If you aren't sure don't proceed - ask for more help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

s.grundy

  • Guest
Re: MBR:Alureon-K [rtk] partion 3
« Reply #14 on: April 05, 2012, 03:19:51 PM »
My grid looks different.  I found Disk 0 but there is no way to delete anything.  I right clicked and all I get is a drop down that lists offline (not accessible), properties, or help.  I am running
Vista, and I have tried every way possible to find partion 3.  I am not doing something right.  Is there any way you could look at a Disk Management grid from a Vista operating machine?
Because I am lost.

Or, is there another way to delete this bogus partition other than by using Disk Management?

« Last Edit: April 05, 2012, 04:18:21 PM by s.grundy »