LOG FILES ADDED only boot safe mode after using ASWmbr fix to get rid of Alureon

I realize that we had exhausted most options (use last known good did not work) but I have a bit more info that may, or may not, prove helpful.

Purchases an adapter to connect the hard drive to another machine via USB. Then ran Malwarbytes which found six infected items. Log is attached. Any other ideas what I might do while I have the drive connected to a different computer? Thanks.

Unfortunately they were just orphan keys and play no part in the boot sequence… I am at a total loss on this now (along with the other people whose brains I have been picking )

So the best bet I feel would be to reinstall after backing up all data

OK. Thanks for all your time and help!

Sorry we could not fix it for you

A miracle happened! I had tried to the rebuildbcd command without results, but in poking around Microsoft I found a reference to the possible need to delete the bcd and back up first, then try the rebuildbcd. Amazing it seems to have worked.

Total beginners luck I would say. I may go buy a lottery ticket.

Is there anything in particular (besides uninstalling Sophos and installing AVAST which I have already done) that should be done in the way of clean up?

OK thank you for that - so delete and then rebuild BCD, sheesh why did we not think of that

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Uninstall ComboFix

Remove Combofix now that we’re done with it.

[*]Please press the Windows Key and R on your keyboard. This will bring up the Run… command.[*]Now copy/paste this: ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /Uninstall, it needs to be there.
[indent]
http://i275.photobucket.com/albums/jj285/Bleeping/Combofix/CFuninstall.gif
[/indent][]Please follow the prompts to uninstall Combofix.[]This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.[*]You will then recieve a message saying Combofix was uninstalled successfully once it’s done uninstalling itself.

Run OTS and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:

[] Go to this site and click Do I have Java
[
] It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point

[*]Go to Control Panel and select System
[*]Select System
[*]On the left select System Protection and accept the warning if you get one
[*]Select System Protection Tab
[*]Select Create at the bottom
[*]Type in a name i.e. Clean
[*]Select Create

Now we can purge the infected ones

[*]GoStart > All programs > Accessories > system tools
[*]Right click Disc cleanup an select run as administrator
[*]Select Your main drive and accept the warning if you get one
[*]For a few moments the system will make some calculations
[*]Select the More Options tab
[*]In the System Restore and Shadow Backups select Clean up
[*]Select Delete on the pop up
[]Select OK
[
]Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:

Thanks, I’ll follow the instructions (so much clearer than any on Microsoft by the way)and report back.

I am assuming I should NOT be running Windows defender along with Avast, is that correct?

It makes no difference to be honest, never had a peep out of defender in all the time I have had it

Do you have a link to the MS page so that I can convert it to plain English

I was actually speaking of the Microsoft (and many other) instructions in general. There is often quite a bit of superfluous information, yet when it comes to the actual instructions to be executed detail is lacking. Your instructions, on the other hand, are refreshingly concise and contain all necessary steps and usually potential results.

The particular page regarding the rebuildbcd was not too bad
http://support.microsoft.com/kb/927392/en-us
but even it did point out that “enter” was required after each step (fairly obvious of course) and it left out the fact that at the end a message would be displayed asking if I wanted to write the result with several options (I forget the actual text, but threw caution to the wind and chose “yes”).

At any rate, thank you for helping all of us with our otherwise insurmountable problems.

Good it was the page I thought

Are these instructions any clearer

Lets rebuild the boot record using the repair option

If the recovery console is already installed i.e you have the full set of options under your safe mode menu then go direct to the red items in the first set of instructions

[]Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
[
]Press a key when you are prompted.
[]Select a language, a time, a currency, a keyboard or an input method, and then click Next.
[
]Click Repair your computer.
[]Click the operating system that you want to repair, and then click Next.
[
]In the System Recovery Options dialog box, click Command Prompt.
[*]Type Bootrec.exe, and then press ENTER.

.

Then type the following commands pressing enter after each line

[]bcdedit /export C:\BCD_Backup
[
]c:
[]cd boot
[
]attrib bcd -s -h -r
[]ren c:\boot\bcd bcd.old
[
]bootrec /RebuildBcd

.
Then restart the computer normally

Much clearer in my opinion. I wish I could remember the exact language of the response I received after running the rebuildbcd. It was something to the effect of:

windows operating system found 1
Do you want to replace the ??? y(yes) n(no) enter(ignore)

not sure about the exact message text or last option.

On my end, I performed all the actions recommended and all seems to be running well. Should I leave ASWmbr? OTS did not delete it.

Also, at some point in the forum it was suggested I get rid of older Java versions. I was not able to run the recommended program but did download and run JavaRa and now cannot find a way to uninstall.

Thanks for all your help.

Javara can be deleted from the desktop along with aswMBR there are no folders/registry items attached

Ta for that I will modify my canned to reflect the other options

In fact I may rebuild my bcd ;D