MBR:Alueron-K issue - logs provided

Hello, please help me!

Avast found a virus named MBR:\.\PHYSICALDRIVE0\Partition2 with status threat: MBR:Alueron-K Rtk . It cannot be moved to chest or deleted. Attached are my logs. (I tried to run aswMBR.exe but it won’'t open…)

How can I vanquish this virus?

another log

(I tried to run aswMBR.exe but it won''t open..)
try run it from safe mode...

also attach Malwarebytes log…

Essexboy is in bed now, but will help you tomorrow…

Thank Pondus. Here are more logs. For unknown reasons I can’t reach the advanced boot options in windows for safe mode. I’m pressing f8 at startup… Not sure if the malware has anything to do with it.

It shouldn’t interfere with your Windows booting as usual rootkits start with Windows. Provided that I know nothing, yet I would suppose it’s a MBR rootkit and well… odd that aswMBR.exe refuses to work. Have you attempted renaming the file to something like iexplore.exe?

Have you attempted using other Fn+F__ combinations? I am almost sure that Windows ALWAYS has Fn+F8 but attempting with other keys won’t cause problems.

If you can’t fix that, do you have your Windows Recovery CD? Most computers these days ship with none, but if you do have one then you could place it in the PC, then go to BIOS, enable booting from external devices (and choose the option to permit you to choose booting method/attempt to boot with external devices first.

Cheers, I hope your problem can be resolved.

Thanks Berxerker. After seeing posts about the same issue I decided to avoid the headache with logs and just reformat my hard-drive. Until Avast can actually remove the virus I think reformatting is the easiest route. BTW, I tried Avira and it didn’t detect the virus. Go avast!

@cyberjunkie
If you still need malware removal help… :wink:

TDSSKiller

[*]Download TDSSKiller and save it to your Desktop.
[*]Unxip the folder (Right Click > Extract to your Desktop).
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application,
[*]Click on Change parametres > check Verify driver signatures and Detect TDLFS file system and then on Start Scan.
[*]If an infected file is detected, the default action will be Cure, click on
[*]If a suspicious file is detected, the default action will be Skip, click on Continue.
[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.
[*]Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the [b]C:[/b] directory.

Combofix

Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Post log reports ( ComboFix.txt) back to topic.