|
| ||||||||||
| Tags: alureon, trojan, virus, win32, windows xp |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
|
|
#2
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
Trojan:Win32/Alureon.CO as the name itself suggest it is kind of trojan which downloads and executes arbitrary files. Some malwares detected with the same name may also be able to spread to removable drives. Whenever this is executed, Trojan:Win32/Alureon.CO creates an event '\\TDKP' to make it sure that only a single instance of the trojan runs at a time. To get rid of this you will have to make use of a good antivirus application on your system. |
|
#3
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
You can make sure whether your system is infected by the trojan by checking the following system changes. In subkey: HKLM\SOFTWARE\Classes\msqpdxvx Adds value: "msqpdxrun" With data: "g" To subkey: HKLM\SOFTWARE\Classes\extravideo\CLSID Sets value: "(default)" With data: "{6bf52a52-394a-11d3-b153-00c04f79faa6}" To subkey: HKLM\SOFTWARE\Classes\msqpdxvx Sets value: "msqpdxpff" With data: <randomly generated letter or number> e.g. "k" If you notice the above changes then this clearly indicates an infection of your system if not, then i would suggest you to remove the browser defender application and check whether your problem is solved. |
|
#4
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
Trojan:Win32/Alureon.CO injects code into <system folder>spoolsv.exe, with the help of which it is spreaded. This code attempts to copy Trojan:Win32/Alureon.CO to all accessible drives as <drive>\resycled\boot.com. An autorun file is also generated - autorun.inf (detected as Trojan:Win32/Alureon!inf) - in the root of each targeted drive. Both of these files are hidden. The autorun file, <drive>\autorun.inf, points to the copy of Alureon.CO, <drive>\resycled\boot.com. When the removable or networked drive is accessed from another machine supporting the Autorun feature, the malware is launched automatically. Try using Microsoft Security Essential application to remove this trojan
__________________ Truly, if there is evil in this world, it lies within the heart of mankind. -Edward D. Morrison Old soldiers never die- they just fade away. |
|
#5
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
Do you know how to remove the trojan Win32: Alureon-BX with free software. It has infected the memory of my computer running with windows XP. C:\windows\system32\drivers\UACpsxfqueo.sys C: \ windows \ system32 \ drivers \ UACpsxfqueo.sys . I checked the subkeys which are mentioned above and they are changed. But it could not help me to get rid of it. |
|
#6
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
To implement a solution to this topic i will need a log file so it would be better if you can post your log file here i have mentioned the method for posting the log file.
Note: The reports are saved in the folder C: \ RSiT |
|
#7
| ||||
| ||||
| Re: Trojan:Win32/Alureon.CO SUGGESTED REMOVAL
Download the Microsoft security Essential application on your system and install it update the virus definition and scan your system to remove the trojan. In future you can prevent such infection on your machine by following the steps which are mentioned below:
|
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Trojan:Win32/Alureon.CO SUGGESTED REMOVAL" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer working slow due to Trojan:Win32/Alureon.FL | Kasavaraju | Networking & Security | 2 | 29-01-2012 09:18 PM |
| How to remove Trojan: win32/fakesysdef and trojan@winnt/alureon.s. | Barnard | Networking & Security | 8 | 28-08-2011 09:50 AM |
| Remove Trojan.win32.alureon.ct by Microsoft Security Essential | TanmayKishan | Networking & Security | 5 | 30-10-2010 03:54 AM |
| Trojan: Win32/Alureon.CT on Dell Studio | KAMANA | Networking & Security | 6 | 26-11-2009 11:18 PM |
| Removal Instructions for Trojan:Win32/FakeScanti | Rutajit | Networking & Security | 3 | 03-11-2009 11:33 AM |