Alureon Rootkit Striked me bad. HELP Please!
Hello dear Windows Users. This is my first post here, because the problem is so serious that even I couldn't remove it (or I'm not sure i did).Problem: I got infected by the so famous Alureon rootkit.Reason:I believe it was Windows Update. I updated Windows 2 months ago and after that windows had to restart. I restarted windows and it load perfectly, but when i clicked Internet Explorer to make sure there are no new updates ,my computer got attacked by at least 10-13 viruses/worms. My AV -> Avast! Internet Security went crazy it was like: a thread was detected,a thread was detected, a thread was detected, a thread was detected so i didn't waited for it to remove them i was very shocked so i emidietly restarted the computer. That was my BIGGEST mistake. After the restarted avast cleaned a few worms in the temporary folders but those worms were just... a small fry. The real deal is that Alureon that got injected somewhere.Symptoms: - The Internet Explorer massive attack. - Blue Screens of Death on startup pointing to important system files, windows loads after the 5-th restart.- Sometimes i get Folders Restrictions -> Your current security settings do not allow you.. bla bla (settings change)What have i used to optimize the pc and remove the errors & viruses (Optimizors) :- Win XP Optimizer: 4 times - Error Repair Professional: 4 times- Speed UP My PC: 4 times- PC Health Advisor: 4 times- Driver Scanner: 4 times- CCleaner: 4 times- Registry Mechanic: 4 times- Advanced System Optimizer: 4 times - Your Uninstaller: 4 times- HiJackThis: 2 times- Microsoft Malicious Software Removal Tool: 2 times- Avast! Internet Security: 1 all disks, normal, max and 1 System Boot Scan I've tried even more stuff (those are my usual optimizers)... nothingI would like to add:It was much more bad then it sounds in the beginning. It even tried to still some of my acc's, now all that is left are the Blue Screens on startup. Avast! Security is one of the best AV's out there it scans everything that's happening and i have no notifications of rootkits since it happened. I know that it hides it's self but i can't even see it running in task manager... I guess it runs only till windows loads... PLEASE HELP ME! P.S.:- Formating Disks, Reinstalling Windows, Updating to Windows Vista/7 or Linux or any other O.S. are not an option.1 person needs an answerI do too
December 27th, 2010 7:45pm

Hello dear Windows Users. This is my first post here, because the problem is so serious that even I couldn't remove it (or I'm not sure i did).Problem: I got infected by the so famous Alureon rootkit.Reason:I believe it was Windows Update. I updated Windows 2 months ago and after that windows had to restart. I restarted windows and it load perfectly, but when i clicked Internet Explorer to make sure there are no new updates ,my computer got attacked by at least 10-13 viruses/worms. My AV -> Avast! Internet Security went crazy it was like: a thread was detected,a thread was detected, a thread was detected, a thread was detected so i didn't waited for it to remove them i was very shocked so i emidietly restarted the computer. That was my BIGGEST mistake. After the restarted avast cleaned a few worms in the temporary folders but those worms were just... a small fry. The real deal is that Alureon that got injected somewhere.Symptoms: - The Internet Explorer massive attack. - Blue Screens of Death on startup pointing to important system files, windows loads after the 5-th restart.- Sometimes i get Folders Restrictions -> Your current security settings do not allow you.. bla bla (settings change)What have i used to optimize the pc and remove the errors & viruses (Optimizors) :- Win XP Optimizer: 4 times - Error Repair Professional: 4 times- Speed UP My PC: 4 times- PC Health Advisor: 4 times- Driver Scanner: 4 times- CCleaner: 4 times- Registry Mechanic: 4 times- Advanced System Optimizer: 4 times - Your Uninstaller: 4 times- HiJackThis: 2 times- Microsoft Malicious Software Removal Tool: 2 times- Avast! Internet Security: 1 all disks, normal, max and 1 System Boot Scan I've tried even more stuff (those are my usual optimizers)... nothingI would like to add:It was much more bad then it sounds in the beginning. It even tried to still some of my acc's, now all that is left are the Blue Screens on startup. Avast! Security is one of the best AV's out there it scans everything that's happening and i have no notifications of rootkits since it happened. I know that it hides it's self but i can't even see it running in task manager... I guess it runs only till windows loads... PLEASE HELP ME! P.S.:- Formating Disks, Reinstalling Windows, Updating to Windows Vista/7 or Linux or any other O.S. are not an option.Alureon is one of the nastiest malware around. Once your computer becomes infected with it it then invites all of it's friends to have a party at your expense. This is not the proper forum to handle such malware. Click on the link below and post your issue on the free computer support forum. Post in the Virus/Malware section. The forum is free.Free forum : Repair-Bots OnlineI don't vote for myself I'm not here for the points. If this post helps you, vote. Visit my forum @ http://repairbotsonline.com/
Free Windows Admin Tool Kit Click here and download it now
December 27th, 2010 8:15pm

The symptoms you describe are not typical of the Alureon rootkit and you don't say why you suspect that infection. In any case, the best tool for detecting and removing same is available athttp://support.kaspersky.com/viruses/solutions?qid=208280684You will have to be able to boot to Windows in safe mode or otherwise to run it though.Running all these "optimizers" and other utilities may have damaged your system beyond repair. If you want to try to salvage this Windows installation I suggest you try to find a qualified professional to help you (which will not be a Big Box store).--"Orlin Kunchev" wrote in message news:Email removed for privacy...Hello dear Windows Users. This is my first post here, because the problem is so serious that even I couldn't remove it (or I'm not sure i did).Problem:* *I got infected by the so famous Alureon rootkit.Reason:*I believe it was Windows Update. I updated Windows 2 months ago and after that windows had to restart. I restarted windows and it load perfectly, but when i clicked Internet Explorer to make sure there are no new updates ,my computer got attacked by at least 10-13 viruses/worms. My AV -> Avast! Internet Security went crazy it was like: a thread was detected,**a thread was detected, **a thread was detected,*a thread was detected so i didn't waited for it to remove them i was very shocked so i emidietly restarted the computer. That was my BIGGEST mistake. After the restarted avast cleaned a few worms in the temporary folders but those worms were just... a small fry. The real deal is that Alureon that got injected somewhere.Symptoms:* **- The Internet Explorer massive attack. *- Blue Screens of Death on startup pointing to important system files, windows loads after the 5-th restart.- Sometimes i get Folders Restrictions -> Your current security settings do not allow you.. bla bla (settings change)What have i used to optimize the pc and remove the errors & viruses (Optimizors) :- Win XP Optimizer: 4 times* *- Error Repair Professional: 4 times- Speed UP My PC: 4 times- PC Health Advisor: 4 times- Driver Scanner: 4 times- CCleaner: 4 times- Registry Mechanic: 4 times*- Advanced System Optimizer: 4 times *- Your Uninstaller: 4 times- HiJackThis: 2 times- Microsoft Malicious Software Removal Tool: 2 times*- Avast! Internet Security: 1 *all disks, normal, max and 1 System Boot Scan** I've tried even more stuff (those are my usual optimizers)... nothingI would like to add:*It was much more bad then it sounds in the beginning. It even tried to still some of my acc's, now all that is left are the Blue Screens on startup. Avast! Security is one of the best AV's out there it scans everything that's happening and i have no notifications of rootkits since it happened. I know that it hides it's self but i can't even see it running in task manager... I guess it runs only till windows loads... PLEASE HELP ME!* P.S.:- Formating Disks, Reinstalling Windows, Updating to Windows Vista/7 or Linux or any other O.S. are not an option.
December 28th, 2010 10:35am

@joelj1964 - Yah... Thanks for nothing...@ GTS-NJ - Mhm, mhm i realized it might not be Alureon, BUT i DID got it thorough Windows Update and yes, i did managed to remove it.This is how i did it:I turned on Avast! Internet Security's shields to the MAXI Ran Kaspersky Lab's tool for the rootkits it found only sptd.sys lockedThe other rootkit removal tools i ran were Sopshos Anti-Rootkit, Gmer, Rootkit Buster, Rootkit Revealer.They found a lot of infected sys files i removed and restered them with clean ones in safe mode (sfc /scannow) (i didn't found that in a big box store as so as the stuff above... i am my only computer specialist, sorry =/)Ran my default optimizers and updated a lot of drivers restoring the infected onesResults: System Running Faster, Booting Faster, There was No 5/10/20 system restarts before windows loads, => WINDOWS LAST 10 UPDATES ACT LIKE THEY WEREN'T INSTALLED! My Question: When will windows updates be safe for Windows XP Users again :((Thank You very much for the replies!
Free Windows Admin Tool Kit Click here and download it now
December 29th, 2010 4:51pm

@joelj1964 - Yah... Thanks for nothing...@ GTS-NJ - Mhm, mhm i realized it might not be Alureon, BUT i DID got it thorough Windows Update and yes, i did managed to remove it.This is how i did it:I turned on Avast! Internet Security's shields to the MAXI Ran Kaspersky Lab's tool for the rootkits it found only sptd.sys lockedThe other rootkit removal tools i ran were Sopshos Anti-Rootkit, Gmer, Rootkit Buster, Rootkit Revealer.They found a lot of infected sys files i removed and restered them with clean ones in safe mode (sfc /scannow) (i didn't found that in a big box store as so as the stuff above... i am my only computer specialist, sorry =/)Ran my default optimizers and updated a lot of drivers restoring the infected onesResults: System Running Faster, Booting Faster, There was No 5/10/20 system restarts before windows loads, => WINDOWS LAST 10 UPDATES ACT LIKE THEY WEREN'T INSTALLED My Question: When will windows updates be safe for Windows XP Users again :((Thank You very much for the replies!With all due respect, you must think we started computer support yesterday. First, with the exception of Avast, each of the scanners you listed are rootkit scanners. If the those scanners had detected "alot of infected sys files" you would not have been able to boot windows.Secondly, sfc /scannow will not run in safe mode. The error you will receive is:Windows File Protection could not initiate a scan of protected system files. The specific error code is 0x000006ba [The RPC server is unavailable.].Third, the detection of sptd.sys by TDSS Killer is a false positive. It is used by several software. Most commonly as a Non-Plug and Play Driver by Daemon Tools.Fourth, there is no such thing as turned on "Avast! Internet Security's shields to the MAXI". The shields are either on or off. If your computer is infected with all those rootkits I am most certain Avast would be disabled and you would not be able to turn it on. Regardless, turning the shields on will not remove threats already infecting the computer.I personally believe your entire post was nothing more than an opportunity to take a shot at Microsoft.Regards,JoelI don't vote for myself I'm not here for the points. If this post helps you, vote. Visit my forum @ http://repairbotsonline.com/
December 29th, 2010 9:25pm

In case of deep system infection when you the above solutions didn't work then contact Microsoft Safety support:https://consumersecuritysupport.microsoft.com/default.aspx?productkey=pcsafetymalware&faq=1&task=diagnostics&st=1&wfxredirect=1
Free Windows Admin Tool Kit Click here and download it now
December 31st, 2010 9:38am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics