Trojan

Trojan:Win32/Alureon!pz information

Malware Removal

The Trojan:Win32/Alureon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Alureon!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Alureon!pz?


File Info:

name: C855BC6179155DB697C8.mlw
path: /opt/CAPEv2/storage/binaries/4c3f9343911c41eca183f0237c5e8343c059218ea2a47660d209dea65cb8ec41
crc32: 11DFF894
md5: c855bc6179155db697c8147716e08d4d
sha1: fd82cfc9f5fd8704968b5c0550f6eb513148e07e
sha256: 4c3f9343911c41eca183f0237c5e8343c059218ea2a47660d209dea65cb8ec41
sha512: 3f29a6d33014bf69c92171a6302c9dd36404c92e74586baefeeb8f06474da007c73aca32c188de65f63f9b006fe417f1c48cf6a2bfa848a2902e97ca28091f53
ssdeep: 12288:6XgPVmsO7H+JeYkZQors8sEyMGXxeulX4EEPSwDfAmgBJbf8AwnBrRm8dZ/X:AoZ3J78GfX4bEmCb+rRvZ/X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBF4BF2273A7DEF3D4262131DC5ADED498519280095BCADA3EE44DA7433AD02DED7372
sha3_384: 0ac5d8677d13fef9522fa8e641e96ce7fc0350483bf778e1fc6aa6e65d883a4bfa44fe158fad52cacc04af900177f9a1
ep_bytes: e8803a0000e978feffff6a0c68f8a345
timestamp: 2011-09-09 12:05:51

Version Info:

0: [No Data]

Trojan:Win32/Alureon!pz also known as:

BkavW32.Common.9CF0F4E2
LionicTrojan.Win32.Mufanom.lrPV
AVGWin32:Hiloti-KK [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.423730
FireEyeGeneric.mg.c855bc6179155db6
CAT-QuickHealTrojan.Amzlcom.A
SkyhighBehavesLike.Win32.PWSZbot.bh
McAfeeGeneric Dropper.ans
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.423730
SangforWorm.Win32.Vobfus.Vq14
K7AntiVirusP2PWorm ( 0055e3e51 )
AlibabaWorm:Win32/Vobfus.28590ce4
K7GWP2PWorm ( 0055e3e51 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.835F06FF1F
VirITWorm.Win32.Generic.AYYU
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.VB.ALI
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Downloader.115127-1
KasperskyWorm.Win32.Vobfus.exgh
BitDefenderGen:Variant.Barys.423730
NANO-AntivirusTrojan.Win32.Crypt.mjwvm
AvastWin32:Hiloti-KK [Trj]
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
EmsisoftGen:Variant.Barys.423730 (B)
BaiduWin32.Worm.VB.qj
F-SecureTrojan.TR/Gendal.kdv.35546
DrWebTrojan.Packed.21911
ZillyaDownloader.Mufanom.Win32.23034
TrendMicroTSPY_MUFANOM_BL130299.TOMC
SophosMal/Generic-S
IkarusTrojan.Win32.Alureon
JiangminTrojanDownloader.Mufanom.ylj
VaristW32/GenTroj.B.gen!Eldorado
AviraTR/Gendal.kdv.35546
Antiy-AVLTrojan[Downloader]/Win32.Mufanom
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Alureon!pz
XcitiumMalware@#1h3q3phbrlww
ArcabitTrojan.Barys.D67732
ViRobotTrojan.Win32.A.Menti.638372
ZoneAlarmWorm.Win32.Vobfus.exgh
GDataGen:Variant.Barys.423730
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R14968
VBA32BScope.Trojan.MTA.01513
ALYacGen:Variant.Barys.423730
MAXmalware (ai score=99)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTSPY_MUFANOM_BL130299.TOMC
TencentTrojan.Win32.Mufanom.bpqc
YandexTrojan.DR.Agent!NWgEDWdKWRI
SentinelOneStatic AI – Suspicious PE
MaxSecureDownloader.Mufanom.bpqc
FortinetW32/Dropper.AAAM!tr
Cybereasonmalicious.179155
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.exgh

How to remove Trojan:Win32/Alureon!pz?

Trojan:Win32/Alureon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment