Posts: 1
Alureon-K
« on: Today at 12:53:46 AM »When I scanned I got the following message : MBR:\.\PHYSICAL DRIVE0\Partiition4 Threat: MBR Alureon-K
When I tried to fix I got Error: The request is not supported Threat MBR Alurion-K
I ran a full boot scan and got the following messages:
FileC:\Documents and Settings\Allsusers\Application Data\Avast Software\Avast\log\unp194787593.tmp.mdmp is infected by MBR:Alureon-K
when I delete and do another full boot scan, the message keeps coming back
FileC:\hiberfil.sys is infected by win32:Hupigon-ONX [TRJ]
when I try to delete I get Delete: error OXC)))))43 a file cannot be opende because the share access flags are incompatible i
File C:\Documents and Settings\Bob Jones\Local Settings\Temproary Internetfiles\content.IE5\E2FXZWN\xtr_new[2].htm is infected by JS:ScriptIP-inf[Trj]
when I try to delete I get An Invalid parameter was passed to a service or function
attached are the logs after running mbam, rougekiller and OTL
RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Bob Jones [Admin rights]
Mode: Scan – Date: 08/23/2012 19:45:07
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: FUJITSU MHW2060BH +++++
— User —
[MBR] dcb594b8d25db6ca7be124d2af2ec37f
[BSP] 26fe7d691f9edb5d824e85e8f49dc627 : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 54070 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 110896695 | Size: 3074 Mo
User = LL1 … OK!
User != LL2 … KO!
— LL2 —
[MBR] 77e11ff8a8c13f3bde4346dea81a2f33
[BSP] 26fe7d691f9edb5d824e85e8f49dc627 : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 54070 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 110896695 | Size: 3074 Mo
3 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 117194175 | Size: 7 Mo
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Bob Jones [Admin rights]
Mode: Scan – Date: 08/23/2012 19:46:45
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: FUJITSU MHW2060BH +++++
— User —
[MBR] dcb594b8d25db6ca7be124d2af2ec37f
[BSP] 26fe7d691f9edb5d824e85e8f49dc627 : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 54070 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 110896695 | Size: 3074 Mo
User = LL1 … OK!
User != LL2 … KO!
— LL2 —
[MBR] 77e11ff8a8c13f3bde4346dea81a2f33
[BSP] 26fe7d691f9edb5d824e85e8f49dc627 : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 54070 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 110896695 | Size: 3074 Mo
3 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 117194175 | Size: 7 Mo
Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt