Search This Blog

Tuesday, February 21, 2012

a week of boot virus - Trojan:DOS/Alureon.E

Trojan:DOS/Alureon.E(?)
Encyclopedia entry
Updated: Dec 05, 2011 | Published: Oct 27, 2011

Aliases
  • Rootkit.MBR.Sst.B (Boot image) (BitDefender)
  • Trojan.DOS.Alureon (Ikarus)
  • Troj/TdlMbr-D (Sophos)



MS security essentials failed to protect (disappointed)

AVG failed to kill, it did killed one file which the virus infected, not the virus itself

tssdkiller and kapersky scan failed to run

nod32 detected it, but failed to kill it. the virus infected dns service, directed all searches to some dodge sites

loaded avast , avast detected it , and identifies as boot virus. But it couldn't kill it in the live system

eventually I pulled out the hard drive from a the lenovo PC, and put it in a USb enclosure, whooopppaa,  doing a scan from my notebook

kapersky reported the boot virus got killed, and MS security essentials also reported it killed the boot virus

after serveral rounds of scan, I put the hard drive back to the system , now I can do kapersky scan.

this boot virus / dns / search posioner is a mutant as well, coz it sometimes showing itself gone



load avast









No comments:

Post a Comment