Malware

Win32:Alureon-AEF [Trj] removal instruction

Malware Removal

The Win32:Alureon-AEF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Alureon-AEF [Trj] virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:Alureon-AEF [Trj]?


File Info:

name: 40256B293C39F2A63C29.mlw
path: /opt/CAPEv2/storage/binaries/0615a66771eb5b5076094844997d960febd1a95cf774f1ef56ea4525295d1338
crc32: 28178363
md5: 40256b293c39f2a63c291a6e51cee02a
sha1: 08d04b0c4e7f38dc2753d36ca1df9a694fbbddc3
sha256: 0615a66771eb5b5076094844997d960febd1a95cf774f1ef56ea4525295d1338
sha512: f2fab6f3073ec9de80eb7255132f116a45bc4633c269d4190037c60c5ae96ef349820e7c5d33344cbea371f39a191f79e92d3349e09af6d0c53725218f669b22
ssdeep: 1536:3ocW1n5q9kP1AReZeT4C1L+zFCiCCeOeyR3QiNpPcl4tr4ShPDf5jH2MGYEfD0:v92UeeHkAipvclSrv1DxH2MGXr0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160A3F191A8604933D9B7DBF00EAF652B1826571F0B7273D381CD330A1F6ADC7A63159A
sha3_384: acbcaa698d226441fedda319d0d40e1f3d6cec147f4edb87c5529e649308090aacc06a43695d494369d7c32a1c7776c2
ep_bytes: cccc6a01e829ffffffa360c161008bc4
timestamp: 2011-06-03 12:13:45

Version Info:

0: [No Data]

Win32:Alureon-AEF [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.40256b293c39f2a6
CAT-QuickHealTrojan.FakeAV
SkyhighBehavesLike.Win32.Generic.nh
McAfeeArtemis!40256B293C39
SangforTrojan.Win32.Agent.V6rl
K7AntiVirusTrojan ( 001e60c61 )
AlibabaTrojan:Win32/FakeAlert.7d1b8029
K7GWTrojan ( 001e60c61 )
Cybereasonmalicious.c4e7f3
SymantecTrojan.FakeAV!gen60
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Alureon-AEF [Trj]
F-SecureTrojan.TR/Kazy.25447.AB
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Kazy
GoogleDetected
AviraTR/Kazy.25447.AB
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.FakeAV.SRP@4m359l
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/FakeAlert.QJ.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R46816
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.FakeSysdef!8.B3D (TFE:1:1Koi3EMjeBR)
SentinelOneStatic AI – Malicious PE
FortinetW32/Jorik.FR!tr
AVGWin32:Alureon-AEF [Trj]
DeepInstinctMALICIOUS

How to remove Win32:Alureon-AEF [Trj]?

Win32:Alureon-AEF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment