Categories: SpyTrojan

TrojanSpy:Win32/Alinaos.A removal

The TrojanSpy:Win32/Alinaos.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Alinaos.A virus can do?

  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine TrojanSpy:Win32/Alinaos.A?


File Info:

crc32: D09EB4BDmd5: 956f0dd85ef3ec90ddf2090b8db9d8c2name: n.exesha1: cd7b8ddc7c8ef4d0db480ec4b7ee40bc9343ffc5sha256: b00a24f6f880bcf43a5d811e24cb0e0c7866e46628a8a6b9e947437c3e791912sha512: 4d733a28211629756f3c9f129d4344804970d9f461cc758b64b0f246dbbf2729099f45fcabd7e92a71c11343593799f59bbb790da80f603e1e1cc975d83973c9ssdeep: 3072:Mydp70Kw0Kgp+33pDmaO+0PDGSXU3HvGG:TdN0sgmnPUXvGGtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Alinaos.A also known as:

Bkav W32.DustonerZSE.Trojan
MicroWorld-eScan Gen:Variant.Zusy.122157
CAT-QuickHeal TrojanSpy.Alinaos.A3
McAfee GenericRXAV-FY!956F0DD85EF3
Cylance Unsafe
TheHacker Trojan/Alinaos.b
K7GW Trojan ( 004bdcb41 )
K7AntiVirus Trojan ( 004bdcb41 )
TrendMicro BKDR_ALINA.SMB
Baidu Win32.Trojan.WisdomEyes.16070401.9500.9913
F-Prot W32/Trojan2.OPNX
Symantec Infostealer.Alina
TrendMicro-HouseCall BKDR_ALINA.SMB
Avast Win32:Alinaos-A [Trj]
ClamAV Win.Trojan.Alina-5
Kaspersky Trojan-Spy.Win32.Alinaos.e
BitDefender Gen:Variant.Zusy.122157
NANO-Antivirus Trojan.Win32.FakeAV.crfguh
Ad-Aware Gen:Variant.Zusy.122157
Emsisoft Gen:Variant.Zusy.122157 (B)
Comodo TrojWare.Win32.Alinaos.B
F-Secure Gen:Variant.Zusy.122157
DrWeb Trojan.FakeAV.16014
VIPRE Trojan.Win32.Generic!BT
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Backdoor.ch
Sophos Troj/Trackr-AI
Ikarus Trojan.Win32.Alinaos
Cyren W32/Trojan.HQIN-1709
Jiangmin TrojanSpy.Agent.wxn
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1030334
Fortinet W32/Agent.CJQO!tr.spy
Antiy-AVL Trojan[Spy]/Win32.Agent
Endgame malicious (high confidence)
Microsoft TrojanSpy:Win32/Alinaos.A
SUPERAntiSpyware Trojan.Agent/Gen-Alinaos
ZoneAlarm Trojan-Spy.Win32.Alinaos.e
TACHYON Trojan-Spy/W32.Agent.141824.N
AhnLab-V3 Malware/Win32.Generic.C472754
ALYac Gen:Variant.Zusy.122157
AVware Trojan.Win32.Generic!BT
MAX malware (ai score=88)
VBA32 TrojanSpy.Agent
Malwarebytes PUP.Optional.Amonetize
Panda Generic Malware
ESET-NOD32 a variant of Win32/Alinaos.B
Rising Spyware.Alinaos!8.7F1F (RDM+:cmRtazoVco1wr2+YEa0GL90MRksF)
SentinelOne static engine – malicious
GData Win32.Worm.Alinaos.B
AVG Win32:Alinaos-A [Trj]
Cybereason malicious.85ef3e
CrowdStrike malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM10.1.C9E1.Malware.Gen

How to remove TrojanSpy:Win32/Alinaos.A?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Malware.AI.1865006162”?

The Malware.AI.1865006162 is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

Trojan.Win32.Agent.xbnsym removal guide

The Trojan.Win32.Agent.xbnsym is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

Backdoor:Win32/AsyncRAT removal tips

The Backdoor:Win32/AsyncRAT is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

Win32:VB-NPD [Wrm] removal instruction

The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is…

39 mins ago

About “Symmi.4579” infection

The Symmi.4579 is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

What is “Lazy.487114”?

The Lazy.487114 is considered dangerous by lots of security experts. When this infection is active,…

46 mins ago