Threat Database Trojans Win32/Alureon.EC

Win32/Alureon.EC

By GoldSparrow in Trojans

Win32/Alureon.EC is a data-stealing Trojan infection which enables cyber-criminals to intercept incoming and outgoing Internet traffic in order to steal private details such as user names, passwords, credit card data, etc. Win32/Alureon.EC may also allow cyber-criminals to send harmful data to the corrupted PC system. Win32/Alureon.EC may modify DNS settings on the host computer to allow the cyber-criminal to accomplish these tasks; therefore, you might reconfigure DNS settings after Win32/Alureon.EC is uninstalled from the compromised machine. Delete Win32/Alureon.EC from the targeted PC as soon as possible.

File System Details

Win32/Alureon.EC may create the following file(s):
# File Name Detections
1. %Program Files%\Protection Center\protext.dll
2. %Documents and Settings%\[UserName]\Start Menu\ Scan.lnk

Registry Details

Win32/Alureon.EC may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'Protection Center'v
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'
HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \CurrentVersion \RunServicesOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'tmp'
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon 'Shell' = '%UserProfile%\Application Data\antispy.exe'

Trending

Most Viewed

Loading...