lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

I have a laptop that has something seriously wrong...an IM was received on aim the other day saying look at this pic....and it turned out to be something bad.... computer is very slow on start up and as soon as it starts avast pops up saying malware was found... Info ...


Reply
 
Thread Tools
  #1  
Old 10th Jun 2009, 18:15
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

I have a laptop that has something seriously wrong...an IM was received on aim the other day saying look at this pic....and it turned out to be something bad....

computer is very slow on start up and as soon as it starts avast pops up saying malware was found...

Info from avast is

File name: C:\\windows\system32\SKYNETievebpws.dll
Malware name: Win32:Alureon-BH [RTK]
Malware type: Rootkit

At the bottom of the screen above the system tray avast says C:\\windows\system32\SKYNETievebpws.dll contains a sample of Win32:Alureon-BH [RTK]


any help is appreciated......???evil??? thanks in advance
  #2  
Old 10th Jun 2009, 23:22
Malware Group
 
Skill Level: Advanced
Posts: 301
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

Hi there

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/comb...o-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.

Once done....

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.


    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop and copy and paste this in your next reply


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Post back with the results form both logs
__________________
Proud member of ASAP & UNITE
__________________

My System: Steves Rig

Processor(s):
AMD Athlon 64x2 6000+
Motherboard:
ASUS M3N78 Pro
RAM Memory:
Corsair 4GB Dual Channel
Graphics Card(s):
NVIDIA GeForce 8400 GS
Sound Card:
Onboard
Hard Drive(s):
640GB Western Digital HD
Optical Drive(s):
LG Lightscribe
Case / PSU:
Cooling:
Stock HSF
Network / Internet:
20Mb Virgin Media Broadband
Monitor(s):
Hanns-G 19" Widescreen
Operating System(s):
Vista Premium 64x
  #3  
Old 11th Jun 2009, 08:37
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

Thanks for the response....i will not be able to get to this until tomorrow, but i will post results once completed
  #4  
Old 11th Jun 2009, 08:43
Malware Group
 
Skill Level: Advanced
Posts: 301
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

Thanks for the update
__________________
Proud member of ASAP & UNITE
  #5  
Old 17th Jun 2009, 12:05
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

SJB...sorry for the delay....i will be on tonight to start the repair on this...i should be on around 7pm EST to get working on it....i will post logs once ran....thanks buddy
  #6  
Old 17th Jun 2009, 17:57
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

i tried running combofix and when i run it i receive this message:




Any ideas? i did not run GMER because you stated i should run combofix 1st.....please let me know....thanks
  #7  
Old 17th Jun 2009, 23:48
Malware Group
 
Skill Level: Advanced
Posts: 301
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

Hi there

I'd like to confirm what I feel will be bad news for you. If I am correct then it will mean a format of this machine

Please go to: VirusTotal

In the middle of the page you'll find a "Browse" button.



Click the "Browse" button and browse to this file in RED:

C:\WINDOWS\system32\winlogon.exe

Click "Open".
Then click the "Send File" button at the bottom of the VirusTotal page.
This will scan the file. Please be patient.
If you get a message saying File has already been analysed: click Reanalyse file now



Copy and then Paste the scan results in your next reply.

Do the same with:

C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\explorer.exe
__________________
Proud member of ASAP & UNITE
  #8  
Old 18th Jun 2009, 05:17
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

Yes this is what i thought if true....i will do as you said and post results.....thank you
  #9  
Old 18th Jun 2009, 17:08
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

alright SJB i see you are on...i am starting with the scans right now and will post once done
  #10  
Old 18th Jun 2009, 17:10
Member Group
 
Posts: 266
Default Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal

when i go to virustotal i get a page load error....happening for anyone else???
Reply

Donate

Register

Bookmarks

Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Removal Logs - Bad Times Paul4763 Virus, Spyware & Security 9 12th Aug 2009 18:06
Win32:Alureon-BH [RTK] Rootkit gingersonny gingersonny Virus, Spyware & Security 36 27th Jun 2009 17:50
Help with malware removal joeshcosmo Virus, Spyware & Security 3 22nd Jan 2009 11:48
Malware Removal - Help VNani Virus, Spyware & Security 23 9th Apr 2008 17:29
Following malware removal instructions, have some questions. jcastell Virus, Spyware & Security 17 19th Feb 2008 18:18
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.