Security Essentials won't remove Win32/Alureon.h
A recent scan by Security Essentials revealed this Trojan in my system, and asks me if I want to remove it, but when I select to remove it, it just goes on and on. It goes through the steps of removing it, then says I need to re-start to complete it, but when I re-start, it's still on there, and the whole process begins again, an endless loop. I have even tried un-installing Security Essentials and re-installing it and then completing a full scan to attempt to remove this, but it still won't go away. Any ideas on how to accomplish this?
January 31st, 2011 8:31pm

Download the free Malwarebytes' Anti-Malware from http://www.malwarebytes.org/
Free Windows Admin Tool Kit Click here and download it now
February 1st, 2011 3:35am

Try the Kaspersky TDSSKiller - How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)MowGreen Windows Expert IT Pro - Consumer Security *-343-* FDNY NEVER FORGOTTEN
February 2nd, 2011 7:14pm

Hi Tokevini, Unfortunately, most of the security programs does not detect this Rootkit (Alureon, as microsoft coined it). Or may be they ignore the presence of alureon. Sorry, i wont tell you the reason. but Kaspersky Labs tdsskiller is effective in detecting the presence of Rootkit and removes it. Symptoms of the prsence of Alureon virus/Rootkitare as follows: Your browser may redirect to some Shopping websites. You cannot access Windows Update site (in XP, you get Page Cannot Be Displayed) and in Vista/Win7. The update error will be 80072EFE) WMI will not see you C Drive Partition. ( Try to open RUN and then type DISKMGMT.MSC. windows will see/detect your CD ROM drive but not the Active Partition. Allright.. thats technical stuff.. How to remove the Virus. Download and run TDSSKILLER from this link. (Thanks Kaspersky Labs) http://support.kaspersky.com/downloads/utils/tdsskiller.exe Run it. It wil detect a Rootkit, mostly MBR infection. Restart the computer to remove the infection. Regards Ramesh Asari
Free Windows Admin Tool Kit Click here and download it now
February 5th, 2011 9:25am

Hi Tokevinl, If you are willing I'll help you remove it manually for no charge. Prepare the following: 1. Time/Day :) 2. Download hiew ( http://www.brothersoft.com/hiew-76223.html ) we will just use the shareware for binary analysis. 3. And then lets submit it here so we can help other people who have the same concern as you. https://www.microsoft.com/security/portal/Submission/Submit.aspxMVP Windows Security
February 5th, 2011 6:04pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics