Vista infected with Alureon.E - Please Help...

View previous topic View next topic Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Wed Jan 25, 2012 1:25 am

To wipe the drive clean, [You must be registered and logged in to see this link.] and reinstall the OS.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Wed Jan 25, 2012 2:53 am

Questions:

1. Should I follow the instructions on the re-format link you sent?
2. My computer never came with an OS disk, only a separate hard drive used for recovery/restore - what should I do with that?
3. Do I need to figure out what drivers I need as shown in the link, or will my recovery partition have all that.

I guess what I'm asking for is a little more individualized instruction applicable to my system. Thanks!!!

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Wed Jan 25, 2012 7:51 pm

How to run the Vista Recovery Console.

1. Eject and remove any discs or memory cards from your computer.
2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart".
3. Hold the "F8" key on your computer's keyboard as Windows Vista reboots
4. Highlight and select "Repair your computer" choose your keyboard type and click "Next".
5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Wed Jan 25, 2012 10:49 pm

I did that. I get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Diagnostic Tool
Command Prompt
Recovery Manager

I went to Recovery Manager, then System Recovery, Then restore to original factory condition. I didn't do it again because that's what I did when I posted my original question a couple weeks ago - trojan was still present. Do I need to buy the CD from HP or can we try something else?

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Thu Jan 26, 2012 2:14 am

Do I need to buy the CD from HP or can we try something else?.
Let's try a few more scans first.

Please download MBRCheck.exe by a_d_13 from one of the links provided below and save it to your desktop.

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

•Double-click on MBRCheck.exe to run it.

•It will open a black window...please do not fix anything (if it gives you an option).

•When complete, you should see Done! Press ENTER to exit.... Press Enter on the keyboard.

•A log named MBRCheck_date_time.txt (i.e. MBRCheck_07.21.10_10.22.51.txt) will appear on the desktop.
•Please copy and paste the contents of that log in your next reply.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Thu Jan 26, 2012 2:58 am

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6700 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 146):
0x01C59000 \SystemRoot\system32\ntoskrnl.exe
0x01C13000 \SystemRoot\system32\hal.dll
0x00606000 \SystemRoot\system32\kdcom.dll
0x00610000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064B000 \SystemRoot\system32\PSHED.dll
0x0065F000 \SystemRoot\system32\CLFS.SYS
0x006BC000 \SystemRoot\system32\CI.dll
0x00809000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008AD000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x008BC000 \SystemRoot\system32\drivers\acpi.sys
0x00912000 \SystemRoot\system32\drivers\WMILIB.SYS
0x0091B000 \SystemRoot\system32\drivers\msisadrv.sys
0x00925000 \SystemRoot\system32\drivers\pci.sys
0x00955000 \SystemRoot\System32\drivers\partmgr.sys
0x0096A000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x0096E000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x0097A000 \SystemRoot\system32\drivers\volmgr.sys
0x0098E000 \SystemRoot\System32\drivers\volmgrx.sys
0x009F4000 \SystemRoot\system32\drivers\intelide.sys
0x0076E000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x0077E000 \SystemRoot\System32\drivers\mountmgr.sys
0x00A06000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x00B0A000 \SystemRoot\system32\drivers\atapi.sys
0x00B12000 \SystemRoot\system32\drivers\ataport.SYS
0x00B36000 \SystemRoot\system32\drivers\msahci.sys
0x00B40000 \SystemRoot\system32\drivers\fltmgr.sys
0x00B87000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C0F000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E03000 \SystemRoot\system32\drivers\ndis.sys
0x00C96000 \SystemRoot\system32\drivers\msrpc.sys
0x00CE6000 \SystemRoot\system32\drivers\NETIO.SYS
0x01003000 \SystemRoot\System32\drivers\tcpip.sys
0x01177000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0120D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0138D000 \SystemRoot\system32\drivers\volsnap.sys
0x013D1000 \SystemRoot\System32\Drivers\spldr.sys
0x013D9000 \SystemRoot\System32\Drivers\mup.sys
0x011A3000 \SystemRoot\System32\drivers\ecache.sys
0x013EB000 \SystemRoot\system32\drivers\disk.sys
0x011CF000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x01200000 \SystemRoot\system32\drivers\crcdisk.sys
0x02310000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0231C000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x02325000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x0232A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x02333000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02404000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x02C0B000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02CEE000 \SystemRoot\System32\drivers\watchdog.sys
0x02CFE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02D0A000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02D50000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x02E02000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x03002000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
0x03494000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
0x034B9000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x034CB000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x034DB000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x034FB000 \SystemRoot\system32\DRIVERS\rimmpx64.sys
0x0350F000 \SystemRoot\system32\DRIVERS\rimspx64.sys
0x03526000 \SystemRoot\system32\DRIVERS\rixdpx64.sys
0x0357D000 \SystemRoot\system32\DRIVERS\HpqRemHid.sys
0x03580000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x03592000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x0359A000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x035B0000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x035BC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x02EEF000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x035CA000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x035CC000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x035D8000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02F42000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x02F7B000 \SystemRoot\system32\DRIVERS\storport.sys
0x02FD8000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02D61000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x035F4000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x02D84000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x02FE5000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02DB5000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x02DD3000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x02DEB000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03000000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02B5F000 \SystemRoot\system32\DRIVERS\ks.sys
0x02FF5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02B93000 \SystemRoot\system32\DRIVERS\umbus.sys
0x02BA3000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x02C00000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x02BEB000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05E0E000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x05F3A000 \SystemRoot\system32\drivers\portcls.sys
0x05F75000 \SystemRoot\system32\drivers\drmk.sys
0x05F98000 \SystemRoot\system32\drivers\ksthunk.sys
0x06008000 \SystemRoot\system32\DRIVERS\smserial.sys
0x0613C000 \SystemRoot\system32\drivers\modem.sys
0x0614B000 \SystemRoot\system32\drivers\MODEMCSA.sys
0x06158000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0x06189000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x06193000 \SystemRoot\System32\Drivers\Null.SYS
0x0619C000 \SystemRoot\System32\drivers\vga.sys
0x061AA000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x061CF000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x061D8000 \SystemRoot\system32\drivers\rdpencdd.sys
0x061E1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x061EC000 \SystemRoot\System32\Drivers\Npfs.SYS
0x05F9E000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x05FA7000 \SystemRoot\system32\DRIVERS\tdx.sys
0x05FC4000 \SystemRoot\system32\DRIVERS\smb.sys
0x02346000 \SystemRoot\system32\drivers\afd.sys
0x023B1000 \SystemRoot\System32\DRIVERS\netbt.sys
0x05FDF000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x00FD4000 \SystemRoot\system32\DRIVERS\pacer.sys
0x05FEA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x00D3F000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x00D5A000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x05E00000 \SystemRoot\system32\drivers\nsiproxy.sys
0x00DA7000 \SystemRoot\System32\Drivers\dfsc.sys
0x02200000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06402000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x06506000 \SystemRoot\System32\drivers\Dxapi.sys
0x06512000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00420000 \SystemRoot\System32\TSDDD.dll
0x006F0000 \SystemRoot\System32\cdd.dll
0x06525000 \SystemRoot\system32\drivers\luafv.sys
0x06547000 \SystemRoot\system32\drivers\spsys.sys
0x065E1000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x0220E000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x065F5000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x02242000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0225A000 \SystemRoot\system32\drivers\HTTP.sys
0x00DC4000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x00B9B000 \SystemRoot\system32\DRIVERS\bowser.sys
0x00BB9000 \SystemRoot\System32\drivers\mpsdrv.sys
0x00BD3000 \SystemRoot\system32\drivers\mrxdav.sys
0x00791000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x17205000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x1724E000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x1726D000 \SystemRoot\System32\DRIVERS\srv2.sys
0x1729F000 \SystemRoot\System32\DRIVERS\srv.sys
0x17332000 \SystemRoot\system32\DRIVERS\MpNWMon.sys
0x17342000 \SystemRoot\system32\drivers\peauth.sys
0x022FD000 \SystemRoot\System32\Drivers\secdrv.SYS
0x00DED000 \SystemRoot\System32\drivers\tcpipreg.sys
0x007BA000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
0x007D2000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x778D0000 \WINDOWS\System32\ntdll.dll

Processes (total 65):
0 System Idle Process
4 System
548 C:\WINDOWS\System32\smss.exe
616 csrss.exe
652 C:\WINDOWS\System32\wininit.exe
672 csrss.exe
708 C:\WINDOWS\System32\services.exe
724 C:\WINDOWS\System32\lsass.exe
732 C:\WINDOWS\System32\lsm.exe
832 C:\WINDOWS\System32\winlogon.exe
908 C:\WINDOWS\System32\svchost.exe
968 C:\WINDOWS\System32\svchost.exe
1004 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
492 C:\WINDOWS\System32\svchost.exe
592 C:\WINDOWS\System32\svchost.exe
584 C:\WINDOWS\System32\svchost.exe
372 C:\WINDOWS\System32\audiodg.exe
660 C:\WINDOWS\System32\svchost.exe
1032 C:\WINDOWS\System32\SLsvc.exe
1096 C:\WINDOWS\System32\svchost.exe
1228 C:\WINDOWS\System32\svchost.exe
1404 C:\WINDOWS\System32\spoolsv.exe
1428 C:\WINDOWS\System32\svchost.exe
1652 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1948 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
1996 C:\WINDOWS\System32\svchost.exe
2016 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
1820 C:\WINDOWS\System32\taskeng.exe
1876 C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
2156 C:\WINDOWS\System32\svchost.exe
2180 C:\WINDOWS\System32\SearchIndexer.exe
2252 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
2484 C:\WINDOWS\System32\taskeng.exe
2604 C:\WINDOWS\System32\dwm.exe
2704 C:\WINDOWS\explorer.exe
2812 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
2848 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
3008 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3020 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
3036 C:\WINDOWS\RAVCpl64.exe
3044 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
2096 C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
2356 C:\WINDOWS\System32\igfxtray.exe
2536 C:\WINDOWS\System32\hkcmd.exe
2508 C:\WINDOWS\System32\igfxpers.exe
1308 C:\Program Files\Microsoft Security Client\msseces.exe
2760 C:\Program Files\Windows Sidebar\sidebar.exe
3056 C:\Program Files (x86)\HP\QuickPlay\QPService.exe
3108 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
3136 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
3148 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3160 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
3236 C:\WINDOWS\System32\svchost.exe
3260 WmiPrvSE.exe
3332 C:\WINDOWS\System32\igfxsrvc.exe
3816 C:\WINDOWS\System32\svchost.exe
3856 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
3456 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1344 C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
4076 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
2864 C:\WINDOWS\System32\SearchFilterHost.exe
2188 C:\WINDOWS\System32\SearchProtocolHost.exe
1452 dllhost.exe
3280 dllhost.exe
2204 C:\Users\Chuck\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000037`01636400 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMHZ2250BHG2, Rev: 8909

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Thu Jan 26, 2012 8:09 pm

I'm going to check with my colleagues about this. I'll be back.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Thu Jan 26, 2012 9:37 pm

Ok - thanks!

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Sat Jan 28, 2012 12:35 am

Ok. Let's try this:

Run the Vista Recovery Console.

1. Eject and remove any discs or memory cards from your computer.

2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart".

3. Hold the "F8" key on your computer's keyboard as Windows Vista reboots.

4. Highlight and select "Repair your computer" choose your keyboard type and click "Next".

5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.


6. Next type FIXMBR

7. If it ask if you're sure you want to write a new MBR, answer 'Y'

8. Then type EXIT to reboot the machine.

9.With that done, please post back and let me know how things are now.


Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Sat Jan 28, 2012 2:13 am

Done as directed - unfortunately, no difference. Any other ideas?

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Sat Jan 28, 2012 2:37 am

Please run the MBR check again and see if there's any change.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Sat Jan 28, 2012 2:55 am

Latest Report:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6700 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 147):
0x01C1C000 \SystemRoot\system32\ntoskrnl.exe
0x02134000 \SystemRoot\system32\hal.dll
0x00609000 \SystemRoot\system32\kdcom.dll
0x00613000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064E000 \SystemRoot\system32\PSHED.dll
0x00662000 \SystemRoot\system32\CLFS.SYS
0x006BF000 \SystemRoot\system32\CI.dll
0x0080B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008AF000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x008BE000 \SystemRoot\system32\drivers\acpi.sys
0x00914000 \SystemRoot\system32\drivers\WMILIB.SYS
0x0091D000 \SystemRoot\system32\drivers\msisadrv.sys
0x00927000 \SystemRoot\system32\drivers\pci.sys
0x00957000 \SystemRoot\System32\drivers\partmgr.sys
0x0096C000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00970000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x0097C000 \SystemRoot\system32\drivers\volmgr.sys
0x00990000 \SystemRoot\System32\drivers\volmgrx.sys
0x009F6000 \SystemRoot\system32\drivers\intelide.sys
0x00771000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x00781000 \SystemRoot\System32\drivers\mountmgr.sys
0x00A0C000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x00B10000 \SystemRoot\system32\drivers\atapi.sys
0x00B18000 \SystemRoot\system32\drivers\ataport.SYS
0x00B3C000 \SystemRoot\system32\drivers\msahci.sys
0x00B46000 \SystemRoot\system32\drivers\fltmgr.sys
0x00B8D000 \SystemRoot\system32\drivers\fileinfo.sys
0x00C04000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E07000 \SystemRoot\system32\drivers\ndis.sys
0x00C8B000 \SystemRoot\system32\drivers\msrpc.sys
0x00CDB000 \SystemRoot\system32\drivers\NETIO.SYS
0x01009000 \SystemRoot\System32\drivers\tcpip.sys
0x0117D000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0120B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0138B000 \SystemRoot\system32\drivers\volsnap.sys
0x013CF000 \SystemRoot\System32\Drivers\spldr.sys
0x013D7000 \SystemRoot\System32\Drivers\mup.sys
0x011A9000 \SystemRoot\System32\drivers\ecache.sys
0x013E9000 \SystemRoot\system32\drivers\disk.sys
0x00FCA000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x01200000 \SystemRoot\system32\drivers\crcdisk.sys
0x02307000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x02313000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x0231C000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x02321000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x0232A000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02403000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x02C02000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02CE5000 \SystemRoot\System32\drivers\watchdog.sys
0x02CF5000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02D01000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02D47000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x02E0B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0320A000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
0x0369C000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
0x036C1000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x036D3000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x036E3000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x03703000 \SystemRoot\system32\DRIVERS\rimmpx64.sys
0x03717000 \SystemRoot\system32\DRIVERS\rimspx64.sys
0x0372E000 \SystemRoot\system32\DRIVERS\rixdpx64.sys
0x03785000 \SystemRoot\system32\DRIVERS\HpqRemHid.sys
0x03788000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x0379A000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x037A2000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x037B8000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x037C4000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x02EF8000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x037D2000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x037D4000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x037E0000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02F4B000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x02F84000 \SystemRoot\system32\DRIVERS\storport.sys
0x02FE1000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02D58000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x02FEE000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x02D7B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x02DAC000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02DBC000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x02DDA000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x02B5E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x037FC000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02B71000 \SystemRoot\system32\DRIVERS\ks.sys
0x02E00000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02BA5000 \SystemRoot\system32\DRIVERS\umbus.sys
0x02BB5000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x02DF2000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x0233D000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06002000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x0612E000 \SystemRoot\system32\drivers\portcls.sys
0x06169000 \SystemRoot\system32\drivers\drmk.sys
0x0618C000 \SystemRoot\system32\drivers\ksthunk.sys
0x06208000 \SystemRoot\system32\DRIVERS\smserial.sys
0x0633C000 \SystemRoot\system32\drivers\modem.sys
0x0634B000 \SystemRoot\system32\drivers\MODEMCSA.sys
0x06358000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0x06389000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x06393000 \SystemRoot\System32\Drivers\Null.SYS
0x0639C000 \SystemRoot\System32\drivers\vga.sys
0x063AA000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x063CF000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x063D8000 \SystemRoot\system32\drivers\rdpencdd.sys
0x063E1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x063EC000 \SystemRoot\System32\Drivers\Npfs.SYS
0x06192000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x0619B000 \SystemRoot\system32\DRIVERS\tdx.sys
0x061B8000 \SystemRoot\system32\DRIVERS\smb.sys
0x02351000 \SystemRoot\system32\drivers\afd.sys
0x023BC000 \SystemRoot\System32\DRIVERS\netbt.sys
0x061D3000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x061DE000 \SystemRoot\system32\DRIVERS\pacer.sys
0x011E3000 \SystemRoot\system32\DRIVERS\netbios.sys
0x00D34000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03200000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
0x011F2000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
0x00D4F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x00D9C000 \SystemRoot\system32\drivers\nsiproxy.sys
0x00DA8000 \SystemRoot\System32\Drivers\dfsc.sys
0x02200000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06609000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x000E0000 \SystemRoot\System32\win32k.sys
0x0670D000 \SystemRoot\System32\drivers\Dxapi.sys
0x06719000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00470000 \SystemRoot\System32\TSDDD.dll
0x00630000 \SystemRoot\System32\cdd.dll
0x0672C000 \SystemRoot\system32\drivers\luafv.sys
0x0674E000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x06762000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x06796000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x067A1000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0220E000 \SystemRoot\system32\drivers\spsys.sys
0x17609000 \SystemRoot\system32\drivers\HTTP.sys
0x176AC000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x176D5000 \SystemRoot\system32\DRIVERS\bowser.sys
0x176F3000 \SystemRoot\System32\drivers\mpsdrv.sys
0x1770D000 \SystemRoot\system32\drivers\mrxdav.sys
0x17734000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x1775D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x177A6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x177C5000 \SystemRoot\System32\DRIVERS\srv2.sys
0x17805000 \SystemRoot\System32\DRIVERS\srv.sys
0x17898000 \SystemRoot\system32\drivers\peauth.sys
0x1794E000 \SystemRoot\System32\Drivers\secdrv.SYS
0x17959000 \SystemRoot\System32\drivers\tcpipreg.sys
0x17969000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
0x17981000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x772F0000 \WINDOWS\System32\ntdll.dll

Processes (total 65):
0 System Idle Process
4 System
532 C:\WINDOWS\System32\smss.exe
616 csrss.exe
652 C:\WINDOWS\System32\wininit.exe
672 csrss.exe
708 C:\WINDOWS\System32\winlogon.exe
748 C:\WINDOWS\System32\services.exe
760 C:\WINDOWS\System32\lsass.exe
768 C:\WINDOWS\System32\lsm.exe
940 C:\WINDOWS\System32\svchost.exe
1000 C:\WINDOWS\System32\svchost.exe
232 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
576 C:\WINDOWS\System32\svchost.exe
604 C:\WINDOWS\System32\svchost.exe
660 C:\WINDOWS\System32\svchost.exe
1036 C:\WINDOWS\System32\audiodg.exe
1056 C:\WINDOWS\System32\svchost.exe
1072 C:\WINDOWS\System32\SLsvc.exe
1120 C:\WINDOWS\System32\svchost.exe
1224 C:\WINDOWS\System32\svchost.exe
1532 C:\WINDOWS\System32\spoolsv.exe
1568 C:\WINDOWS\System32\svchost.exe
1768 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
1812 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1976 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
2036 C:\WINDOWS\System32\svchost.exe
1136 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
2180 C:\WINDOWS\System32\taskeng.exe
2228 C:\WINDOWS\System32\dwm.exe
2248 C:\WINDOWS\explorer.exe
2328 C:\WINDOWS\System32\taskeng.exe
2548 MpCmdRun.exe
2624 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2632 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
2648 C:\WINDOWS\RAVCpl64.exe
2660 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
2768 C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
2796 C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
2804 C:\WINDOWS\System32\igfxtray.exe
2848 C:\WINDOWS\System32\svchost.exe
2892 C:\WINDOWS\System32\SearchIndexer.exe
2948 C:\WINDOWS\System32\hkcmd.exe
2956 C:\WINDOWS\System32\igfxpers.exe
2968 C:\Program Files\Microsoft Security Client\msseces.exe
2976 C:\Program Files\Windows Sidebar\sidebar.exe
2996 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
3016 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
2464 C:\Program Files (x86)\HP\QuickPlay\QPService.exe
2536 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
2532 C:\Program Files (x86)\Adobe\Reader 8.0\Reader\reader_sl.exe
1152 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
2756 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
2020 WmiPrvSE.exe
1328 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
2096 C:\WINDOWS\System32\igfxsrvc.exe
2748 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
2132 WmiPrvSE.exe
3180 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
3216 C:\WINDOWS\System32\svchost.exe
3660 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
3836 C:\WINDOWS\System32\svchost.exe
2440 dllhost.exe
3848 dllhost.exe
3352 C:\Users\Chuck\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000037`01636400 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMHZ2250BHG2, Rev: 8909

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Tue Jan 31, 2012 2:06 am

Sorry. Let's try this:

Run the Vista Recovery Console.

1. Eject and remove any discs or memory cards from your computer.

2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart".

3. Hold the "F8" key on your computer's keyboard as Windows Vista reboots.

4. Highlight and select "Repair your computer" choose your keyboard type and click "Next".

5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.

6. Next type bootrec /fixmbr

7. If it ask if you're sure you want to write a new MBR, answer 'Y'

8. Then type EXIT to reboot the machine.

9.With that done, please post back and let me know how things are now.


Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by charger73fan on Thu Feb 02, 2012 8:06 pm

Thanks so much for your time and assistance with this problem, but the wife insisted that I get recovery disks and erase the computer to start from scratch. I did what she wanted and everything's fine now. Whatever that Alureon.E was, it was a pain to remove. One last question - what's your suggestion for free internet/virus security so this doesn't happen again? Thanks so much for your time and help again....

charger73fan
Novice
Novice

Status :
Online
Offline

Posts Posts : 24
Joined Joined : 2012-01-14
OS OS : Vista

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Thu Feb 02, 2012 11:24 pm

I'm sorry it had to come to that but as the saying goes; "happy wife, happy life". Here's some advice.

Remember to only install one antivirus!

1) [You must be registered and logged in to see this link.]
2) [You must be registered and logged in to see this link.]
3) [You must be registered and logged in to see this link.]
4) [You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]
4-a) [You must be registered and logged in to see this link.]
5) [You must be registered and logged in to see this link.] (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) [You must be registered and logged in to see this link.]

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
**************************************************
Remember only install ONE firewall

1) [You must be registered and logged in to see this link.] (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) [You must be registered and logged in to see this link.]
3) [You must be registered and logged in to see this link.]
4) [You must be registered and logged in to see this link.]

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
*****************************************************
I suggest using [You must be registered and logged in to see this link.]. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

[You must be registered and logged in to see this link.]- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* [You must be registered and logged in to see this link.] from Spyware and Malware
* If you don't know what ActiveX controls are, see [You must be registered and logged in to see this link.]

Protect yourself against spyware using the Immunize feature in [You must be registered and logged in to see this link.] Guide: [You must be registered and logged in to see this link.] to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. [You must be registered and logged in to see this link.]

Check out [You must be registered and logged in to see this link.] for tips and free tools to help keep you safe in the future.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Vista infected with Alureon.E - Please Help...

Post by Superdave on Thu Feb 02, 2012 11:26 pm

[You must be registered and logged in to see this link.] wrote:I'm sorry it had to come to that. Here's some advice.

Remember to only install one antivirus!

1) [You must be registered and logged in to see this link.]
2) [You must be registered and logged in to see this link.]
3) [You must be registered and logged in to see this link.]
4) [You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]
4-a) [You must be registered and logged in to see this link.]
5) [You must be registered and logged in to see this link.] (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) [You must be registered and logged in to see this link.]

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
**************************************************
Remember only install ONE firewall

1) [You must be registered and logged in to see this link.] (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) [You must be registered and logged in to see this link.]
3) [You must be registered and logged in to see this link.]
4) [You must be registered and logged in to see this link.]

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
*****************************************************
I suggest using [You must be registered and logged in to see this link.]. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

[You must be registered and logged in to see this link.]- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* [You must be registered and logged in to see this link.] from Spyware and Malware
* If you don't know what ActiveX controls are, see [You must be registered and logged in to see this link.]

Protect yourself against spyware using the Immunize feature in [You must be registered and logged in to see this link.] Guide: [You must be registered and logged in to see this link.] to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. [You must be registered and logged in to see this link.]

Check out [You must be registered and logged in to see this link.] for tips and free tools to help keep you safe in the future.

Superdave
Captain
Captain

Status :
Online
Offline

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum