Author Topic: Infected with MBR:Alureon-K  (Read 12938 times)

0 Members and 1 Guest are viewing this topic.

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #15 on: May 25, 2012, 12:08:03 PM »

Here is the report

Now I will reboot

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #16 on: May 25, 2012, 12:14:19 PM »

The system reboots, but Avast finds:

MBR:Alureon-K in Partition2.

jeffce

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #17 on: May 25, 2012, 01:34:37 PM »
Hi,

Just so you know, we are dealing with quite a nasty infection and this may take a bit of time to completely clear out, but you are doing great!

You mentioned earlier that aswMBR.exe would not run.  Try and give that a run again and if the log is produced please attach that. 

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #18 on: May 25, 2012, 02:07:15 PM »


It run.

Here is the log

jeffce

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #19 on: May 25, 2012, 02:40:02 PM »
Hi,

Copy aswMBR to your root drive i.e.  C:\aswMBR.exe
Click Start > Run
Copy/paste the following command into the box and press enter

aswMBR.exe -ap 1

Once it has completed then reboot and re-run aswMBR and post the log here

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #20 on: May 25, 2012, 03:05:09 PM »

Here is the log.

Note the last report is in second place.

jeffce

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #21 on: May 25, 2012, 04:40:32 PM »
In the run box type the following

diskmgmt.msc

When disc management opens expand it so that all drives are visible
Take a screenshot and post it here

Are you able to burn a CD on another computer ?
-------------

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #22 on: May 25, 2012, 06:06:01 PM »


The screenshot.

Yes, I can burn a CD on another computer?

jeffce

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #23 on: May 25, 2012, 06:15:18 PM »
Hi,

I need you to download:
gparted-live-0.10.0-3.iso (115.1 MB) 

Create a bootable CD, for Gparted from the ISO image.

You can use ImgBurn do this.

Now boot off of the newly created Gparted CD. 



You should be here... Press ENTER



By default, "do not touch keymap" is highlighted.
Leave this setting alone and just press ENTER. 



Choose your language and press ENTER. English is default [33]



Once again, at this prompt, press ENTER 
You will now be taken to the main GUI screen below



According to your logs, the partition that you want to delete is 8 mb

Click the trash can icon to delete and then click Apply.

You should now be here confirming your actions: 

 

Now you should be here:

 



Is "boot" next to your OS drive? 
If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags 

In the menu that pops up, place a checkmark in boot like the picture below:

 


Now double-click the button. 

You should receive a small pop up like this:



Choose reboot and then press OK.

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #24 on: May 25, 2012, 09:58:45 PM »

Only one partition is shown, 111 GB.

Unallocated unallocated 11.79 GiB

If I must delete the 8 MB partition, I can try with TestDisk or another utility.

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #25 on: May 25, 2012, 10:09:15 PM »
Sorry

TestDisk does not delete partitions

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #26 on: May 25, 2012, 11:53:07 PM »

I have deleted the partition with diskpart.

The partition does not appear in diskmgmt.msc

I'm making a quick scan with Avast

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #27 on: May 26, 2012, 12:13:08 AM »

Quick scan is clean

jeffce

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #28 on: May 26, 2012, 01:51:34 AM »
Hi,

Great....do you have that log to attach?  :)

fmf

  • Guest
Re: Infected with MBR:Alureon-K
« Reply #29 on: May 26, 2012, 08:46:11 AM »

Wich log?

Avast? How can I get it?