Trojan

Should I remove “Trojan:Win32/Alureon.BJ”?

Malware Removal

The Trojan:Win32/Alureon.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Alureon.BJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Alureon.BJ?


File Info:

name: 09E1C251FAEB86608A12.mlw
path: /opt/CAPEv2/storage/binaries/26e2bb8181ebf69b1a4c595bc8e157b3e01362354e951c41478f978f6aa176b2
crc32: 791F24CD
md5: 09e1c251faeb86608a12930637c3ba3a
sha1: 0853f1c077edc853d48995592777d421ce91b1be
sha256: 26e2bb8181ebf69b1a4c595bc8e157b3e01362354e951c41478f978f6aa176b2
sha512: f816a7d67c37b8ff995fd02ea7e61ce90e1406102bd79d71d11dc4136d2eab66e9e6a36f77877ccf7fa9f895b04d2e8522ecfd17ac087d14c357f4c623e76efc
ssdeep: 384:OIA/ne7vq4BpPgsls95O9ONGHiRsV1gFpjIKgldEv4ckRMqNwFG8cbjZaQ8Qe2vX:Oxne7vbyOMNXkgFpf2SMhhaBQeKEvs1V
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13BF2D143E7DA6020F9AF7B7300EEE75AAA59B930A034759343147206B770A94DF27399
sha3_384: 2ccda31c2394ad5088a327381daa82ff9e70fff96e7e0171b4a8f0585187d6b686d5fec1f31bb0308743ba1eed7bb50f
ep_bytes: 558bec83ec54837d0c0153568d64a4fc
timestamp: 2065-11-10 03:11:39

Version Info:

CompanyName: Microsoft Corporation
FileVersion: 1,0,0,1392
LegalCopyright: © Microsoft Corporation. All rights reserved.
ProductName: Microsoft® Windows® Operating System
ProductVersion: 1,0,0,1392
Translation: 0x0419 0x04b0

Trojan:Win32/Alureon.BJ also known as:

LionicHacktool.Win32.TDSS.kYMh
MicroWorld-eScanTrojan.TDss.BG
FireEyeGeneric.mg.09e1c251faeb8660
SkyhighBehavesLike.Win32.Virut.nc
McAfeeDNSChanger.eq
ZillyaBackdoor.Neakse.Win32.172
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 000a12991 )
AlibabaVirTool:Win32/Obfuscator.4b18f378
K7GWTrojan ( 000a12991 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.33EA117B21
VirITTrojan.Win32.Vundo.DU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.QFK
APEXMalicious
TrendMicro-HouseCallBKDR_TDSS.SM
ClamAVWin.Trojan.Tdss-3410
KasperskyPacked.Win32.TDSS.z
BitDefenderTrojan.TDss.BG
NANO-AntivirusTrojan.Win32.Monderc.gbzn
AvastWin32:Alureon-V [Trj]
TencentWin32.Packed.Tdss.Itgl
TACHYONTrojan/W32.TDss.34304
EmsisoftTrojan.TDss.BG (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Siggen.5909
VIPRETrojan.TDss.BG
TrendMicroBKDR_TDSS.SM
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Alureon
JiangminBackdoor/Neakse.d
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Backdoor.JFWH-0624
Antiy-AVLTrojan[Packed]/Win32.TDSS
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Alureon.BJ
XcitiumWin32.PkdTDSS.Z@1nz6jq
ArcabitTrojan.TDss.BG
ZoneAlarmPacked.Win32.TDSS.z
GDataTrojan.TDss.BG
CynetMalicious (score: 100)
AhnLab-V3Packed/Win32.Tdss.C93967
VBA32Trojan.Win32.Olmarik.107
ALYacTrojan.TDss.BG
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Alureon!8.227 (TFE:2:bi93SHTAJ4U)
YandexRootkit.Alureon.Gen!Pac.3
SentinelOneStatic AI – Malicious PE
MaxSecurePacked.W32.TDSS.Z
FortinetW32/PackTDss.ZE!tr
AVGWin32:Alureon-V [Trj]
DeepInstinctMALICIOUS
alibabacloudVirtool:Win/TDSS.z

How to remove Trojan:Win32/Alureon.BJ?

Trojan:Win32/Alureon.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment