Trojan

Trojan:WinNT/Alureon.L removal instruction

Malware Removal

The Trojan:WinNT/Alureon.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:WinNT/Alureon.L virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:WinNT/Alureon.L?


File Info:

name: 9A41BCBD0413074EA6DC.mlw
path: /opt/CAPEv2/storage/binaries/8bedf6fb6568a00156e97613adc451e0bcd33e99b0e0bcc9a11446178f284acd
crc32: C3A7F4C8
md5: 9a41bcbd0413074ea6dcd18f9907f0d0
sha1: 157ce52f9e6a28b482cd13b5702bc096c729b3ba
sha256: 8bedf6fb6568a00156e97613adc451e0bcd33e99b0e0bcc9a11446178f284acd
sha512: 57c7233a164828085edba61eaf9ce266fc61ea943fe93bc92df94037236ca61dbd1c8a576f01d935f4bc8d0999f936136360b79e9badfbce1781c244c53ca9b3
ssdeep: 384:xyluKAsGXvRIA6VxP/bIJyApGoYxNON19/hbXbYmJ1xnFuNibYqlbV30:xyUK4RIpL/b/iGoYmXTXXrFuyYwhk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CD2C059B7EF0A7BF1650531A487030649B8AD532BE9A22FD7C319192CB5447ECB0F32
sha3_384: d5f0e126a19235ad23d99e503ab0446be127389fbdfeaec7b56370e35a26ddedb1a505df09a26a6d08334c547534ce0f
ep_bytes: 558d6c249081ecac01000056578b7d78
timestamp: 2010-11-04 11:55:58

Version Info:

CompanyName: VMware, Inc.
FileDescription: VMware PCI VMCI Bus Device
FileVersion: 7.2.30.0
InternalName: vmci.sys
LegalCopyright: Copyright © 1998-2009 VMware, Inc.
OriginalFilename: vmci.sys
ProductName: VMware PCI VMCI Bus Device
ProductVersion: 7.2.30.0 build-189381
Translation: 0x0409 0x04b0

Trojan:WinNT/Alureon.L also known as:

LionicTrojan.Win32.Generic.4!c
DrWebBackDoor.Tdss.7381
MicroWorld-eScanGen:Variant.TDss.48
FireEyeGeneric.mg.9a41bcbd0413074e
ALYacGen:Variant.TDss.48
MalwarebytesMalware.AI.3663136615
ZillyaRootkit.TDSS.Win32.10414
SangforTrojan.Win32.Alureon.V4ge
AlibabaTrojan:Win32/Olmarik.adb7755f
Cybereasonmalicious.d04130
ArcabitTrojan.TDss.48
VirITTrojan.Win32.Crypt.ACBR
CyrenW32/Alureon.AM.gen!Eldorado
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/Olmarik.AGZ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.TDss.48
NANO-AntivirusTrojan.Win32.TDSSPackA.dvbox
AvastWin32:Alureon-JY [Rtk]
TencentWin32.Trojan.Generic.Udkl
TACHYONTrojan/W32.Small.30208.CR
EmsisoftGen:Variant.TDss.48 (B)
F-SecureTrojan.TR/Agent.30720.BY
VIPREGen:Variant.TDss.48
TrendMicroTROJ_GEN.R002C0DDK23
McAfee-GW-EditionGeneric Dropper.amu
SophosMal/TDSSPack-A
JiangminRootkit.TDSS.gdv
AviraTR/Agent.30720.BY
Antiy-AVLTrojan[Rootkit]/Win32.TDSS
XcitiumTrojWare.Win32.Rootkit.Agent.~clj@2f6o0h
MicrosoftTrojan:WinNT/Alureon.L
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.TDss.48
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Tdss.R1726
McAfeeGeneric Dropper.amu
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Tdss
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DDK23
RisingTrojan.Alureon!8.227 (TFE:1:hSlqulsPAYC)
YandexTrojan.GenAsa!zbTSJxvUtSc
IkarusTrojan.WinNT.Alureon
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/PackTDss.X!tr.rkit
AVGWin32:Alureon-JY [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:WinNT/Alureon.L?

Trojan:WinNT/Alureon.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment