Malware

What is “Win32:Alman”?

Malware Removal

The Win32:Alman is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Alman virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32:Alman?


File Info:

crc32: 411D7AD0
md5: 4a977f8c178c30f4426ac43cd5ab9b6a
name: 4A977F8C178C30F4426AC43CD5AB9B6A.mlw
sha1: 0e501478961abc5acdf9ea9b095a1d4d0cc05aa2
sha256: 49af97cddc3027a8d515eebba0bbb10aad82adf33be19f474e20a9cfd40fc3e4
sha512: 1162574540b237e3bccca462a51d82ce8f50e5168795728ed565e46595fcc26c80a3108b11d61343c953adc67875d9bed4972c3413508d8f24e9e02c996d48b9
ssdeep: 12288:xnaopjPkhzL6y5F/yfszHM8xL5c02gKYSsPM:xBRkpL6y5KszsgL00SoM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2010, TP-LINK TECHNOLOGIES CO., LTD. All Rights Reserved.
InternalName: Autorun.exe
FileVersion: 1.0.0.5
CompanyName: TP-LINK TECHNOLOGIES CO., LTD.
ProductName: Autorun
ProductVersion: 1.0.0.5
FileDescription: Autorun
OriginalFilename: Autorun.exe
Translation: 0x0804 0x03a8

Win32:Alman also known as:

BkavW32.AcLuC.PE
K7AntiVirusVirus ( 00001b6e1 )
LionicVirus.Win32.Alman.ljf2
DrWebWin32.Alman.1
CynetMalicious (score: 100)
CMCVirus.Win32.Almanahe.2!O
CAT-QuickHealW32.Almanahe.B
ALYacWin32.Almanahe.D
CylanceUnsafe
ZillyaVirus.Alman.Win32.2
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaVirus:Win32/Alman.103e26b6
K7GWVirus ( 00001b6e1 )
Cybereasonmalicious.c178c3
TrendMicroPE_CORELINK.C-1
BaiduWin32.Virus.Alman.a
CyrenW32/Alman.C
SymantecW32.Almanahe.B!inf
ESET-NOD32Win32/Alman.NAB
ZonerVirus.Win32.16464
APEXMalicious
AvastWin32:Alman
ClamAVWin.Trojan.Alman-6
GDataWin32.Almanahe.D
KasperskyVirus.Win32.Alman.b
BitDefenderWin32.Almanahe.D
NANO-AntivirusVirus.Win32.Alman.xyevp
ViRobotWin32.Alman.B
MicroWorld-eScanWin32.Almanahe.D
TencentVirus.Win32.Magister.a
Ad-AwareWin32.Almanahe.D
SophosW32/Alman-C
ComodoVirus.Win32.Alman.A@18f6pd
F-SecureMalware.W32/Alman.BB
BitDefenderThetaAI:FileInfector.3231077510
VIPREVirus.Win32.Alman.b (v)
Invinceaheuristic
FireEyeGeneric.mg.4a977f8c178c30f4
EmsisoftWin32.Almanahe.D (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Alman.C
Endgamemalicious (high confidence)
AviraW32/Alman.BB
Antiy-AVLVirus/Win32.Alman.b
KingsoftWorm.DLan.c.79872
MicrosoftVirus:Win32/Almanahe.B
JiangminWin32/Almana.c
ArcabitWin32.Almanahe.D
ZoneAlarmVirus.Win32.Alman.b
TACHYONVirus/W32.Alman.B
AhnLab-V3Win32/Alman.C
McAfeeW32/Almanahe.f.c
MAXmalware (ai score=100)
VBA32Virus.Win32.Alman.B
MalwarebytesVirus.Alman
PandaW32/Almanahe.C
TrendMicro-HouseCallPE_CORELINK.C-1
RisingVirus.Almanahe!8.379 (CLOUD)
YandexWin32.Alman.B
IkarusVirus.Alman
MaxSecureVirus.Alman.B
FortinetW32/Alman.B
AVGWin32:Alman
Paloaltogeneric.ml
Qihoo-360Virus.Win32.Alman.C

How to remove Win32:Alman?

Win32:Alman removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment