News Focus
News Focus
icon url

Howzitgoing

09/07/11 3:44 PM

#24632 RE: cintrix #24631

I looked at Win32/Alureon and it's not pretty.

Win32/Alureon is a family of data-stealing trojans. These trojans allow an attacker to intercept incoming and outgoing Internet traffic in order to gather confidential information such as user names, passwords, and credit card data. It may also allow an attacker to transmit malicious data to the infected computer. The trojan may modify DNS settings on the host computer to enable the attacker to perform these tasks. As a result, it may be necessary to reconfigure DNS settings after disinfection.

One of its components can morph into files and registry keys that are randomly named, which, if you have the patience, you may be able to comb through everything and figure them out. However, you have to research the likely destination folders and keys. So, yes, you're right to wonder if everything has been removed.

I can't stress enough that these things find homes in different folders and keys, but just to satisfy your curiosity, look in the following folder as well as any temp folders. Here's one randomly named file I found:

C:\Documents and Settings\UserName\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE(2).1

I haven't looked at the other two viri you mentioned.

If you have the option, and to be safe, I would FDISK - wipe - your hard drive clean - NOT just format it - and reinstall everything. Make sure you wipe all partitions if there's more than one. The reason is that some trojans, including Alureon, I believe, can infect the MBR. So you want to start over with a pristine drive.

Ouch, I know.