Author Topic: I have got Win32 Alureon-EU  (Read 4479 times)

0 Members and 1 Guest are viewing this topic.

E.T

  • Guest
I have got Win32 Alureon-EU
« on: January 05, 2010, 07:06:57 PM »
Hi
I have just got the worm Win32 Alureon-EU. I have searced around in this forum how to get rid of the worm, but i havent got rid of it yet.
I am running Windows Xp sp3.
The file that is infected is the "atapi.sys" file
I Have used Combo-Fix and TDSSKiller as instructed in this posthttp://forum.avast.com/index.php?topic=52369.0
This did not solv my problem though. I restarted after using TDSSKiller and then when my computer was booting i got a bluescreen.
Then i had to choose "Start windows xp with the  Last Known Good Configuration"

I got this txt file from Combo-Fixhttp://www.mediafire.com/?0zymmdjbtzm
 
Im still having trouble with the Worm so i hope someone can help me.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37504
  • Not a avast user

rickdurango

  • Guest
Re: I have got Win32 Alureon-EU
« Reply #2 on: January 12, 2010, 01:21:42 AM »
Thanks Pondus...

E.T., I seemed to have the same problem as you.  I did not do the combo-fix or TDSSKiller, but accidentally deleted the atapi.sys file manually (via My Computer) after the avast window came up many times with Alureon-EU in atapi.sys.  Same thing with the blue screen.  I was eventually able to restart with "Last Known Good Configuration".  I took the risk and reconnected my LAN cable, and went to Windows Live Safety scanner (http://onecare.live.com/site/en-us/default.htm) and did a full scan as per Pondus' link.  While doing this I did a once-over of my system in My Computer and noticed several folders created by the virus full of root files in the drive partition containing my OS (folders had large names of random letters and numbers).  I deleted these folders in My Computer, as well as a program called "Loudmo Contextual Ad Assistant" that intalled itself along with the virus via "Add/Remove Programs" in Control Panel.

While I was running Windows Live Safety Scanner I left Avast running and it did not seem to interfere.  Also, I noticed that the virus turned off my windows firewall, which I turned back on manually, and it installed a couple of add-ons in firefox as well (it would randomly start running firefox and going to specific ad websites and opening the add-on window) which I uninstalled.

I am now able to restart my computer without going back to "Last known good config" and things seem to be running well again.  I will update this post if anything else comes up.

Thanks again for the link Pondus!

CharleyO

  • Guest
Re: I have got Win32 Alureon-EU
« Reply #3 on: January 14, 2010, 08:08:39 AM »
***

Welcome to the forums, rickdurango.   :)

Thanks for posting what worked for you. Hopefully, it will help others.


***