Microsoft Security Essentials

  • Scanning, Detecting, and Removing Threats
  • Microsoft Security Essentials
  • All forums
Question

How do you get ride of Trojan:Win32/Alureon.CT?

MSE can detect it, It just can't seem to get rid of it.  I have also tried Spybot, AVG, Bit Defender, Line One Care and the MSRT. I have tired the online scanners from Mcafee and Symantec, and Trend micro inculding its new rootkit buster. Someone has got to have a way to kill this thing.

The MSE sites says it can remove it but it can't so what do I do?
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation
6 People had
this question

Was this helpful?

Answer
 

Start here - https://support.microsoftsecurityessentials.com/

and select the link that says - I think my computer is infected - and then select the support option for phone (or email if phone is not offered for your region)
-steve


~ Microsoft MVP Windows Live ~ Windows Live OneCare| Live Mesh|MS Security Essentials Forums Moderator ~
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Stephen Boots

Community Moderator
Microsoft MVP Windows Live

Was this helpful?

Were you able to submit the file using the link provided?
http://www.microsoft.com/security_essentials/support.aspx?mkt=en-us&s=3#mainNav

If so, can you provide the submission id? I can follow up once I have it.

If you aren't able to submit a sample, please create a case online as Steve proposed.
They can help remove the malware and also submit a sample.

If you weren't able to submit the file, are you able to check the following registry key:
HKLM\Software\Microsoft\RemovalTools\MRT\Guid
If so, are you able to provide the value to this key?

Thanks, Hazel

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Hazr

Hazr Microsoft

Was this helpful?

I tried that. A helpful guy from Chennai shared my computer, removed my temp files and cookies, ran a scan and found nothing. An hour or so later, we called it a day. Ten minutes afterward - it's Ba-ack!
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

When you don't find answer here and if you find new threat or Malware , please submit samplet to Microsoft and also if you have problem with remove Virus contact MSE support team.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

You might want to take a look at the description of this malware from the Microsoft Malware Protection Center, I really wouldn't trust this system even after the malware itself appeared to be removed, since this malware family does a lot of additional damage.

https://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3aWin32%2fAlureon.CT

I really think that this malware is of a class that requires a clean sweep of the PC to insure its effects are completely gone, so formatting and reinstallation of the operating system is the only sure way for this to occur.  However, if you don't have the reinstall media for your PC or some of the software required to rebuild it, you may be able to get help in removing it through other channels.

See this thread for some options:
http://social.answers.microsoft.com/Forums/en-US/msescan/thread/87058857-d181-4019-a723-efd9a49d9275

Rob
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

I really think that this malware is of a class that requires a clean sweep of the PC to insure its effects are completely gone, so formatting and reinstallation of the operating system is the only sure way for this to occur. 
I do not suggest formating and reinstalling whole operating system. Because eventhough Malware are scary and might go deep to kernel and make system terrible, then we still should find a way to recover it and remove Malware without formatting the system and reinstall it. Format and reinstall is a solution but it is not a good way as long as it might consume time and require back up and restore data.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

I really think that this malware is of a class that requires a clean sweep of the PC to insure its effects are completely gone, so formatting and reinstallation of the operating system is the only sure way for this to occur. 
I do not suggest formating and reinstalling whole operating system. Because eventhough Malware are scary and might go deep to kernel and make system terrible, then we still should find a way to recover it and remove Malware without formatting the system and reinstall it. Format and reinstall is a solution but it is not a good way as long as it might consume time and require back up and restore data.

hi ,

indeed some malware could stay in the memory or in a ghost , run a clean up first , then reinstall , but overwrite all first with a diskcleaner , that will destroy anything on the disk in either random numbers or jus 0 and 1

have a nice day
Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? Learn how to remove it + Threat Research & Response Blog + Sysinternals Live tools + PIVOT from Live Labs + See what Photosynth does best! + Microsoft Security +
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Dabur972

Dabur972
Microsoft SUPPORT >> support.microsoft.com
Microsoft SECURITY >> www.microsoft.com/security

Was this helpful?

Cross fingers for me... I spent more time with Microsoft's valiant virus-fighters in Chennai. This time, he shared my desktop and remotely used Kasperesky's tdss-killer. Seems to have done the job... I've had no zombie-alureon-ct pop-ups for at least 6 hours. (Earlier, they reappeared in 10-20 minutes.)
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Message marked as answers cannot be deleted

To delete this message, first unmark this message as an answer, then delete it.

Reason to remove escalation


Merge

Enter the thread ID of the thread you are merging into


Reply will be posted to a public thread

You are replying to a public portion of this thread. To reply privately, click Cancel, click the Private Messages tab, and Reply on that private message.

Don't show this message again

To report abuse, sign in or continue without signing in

Thank you.

Report abuse

Abuse type:

Details (optional):

Report abuse

Abuse type:

Details (required):
Enter the characters you see (required):
Type the numbers that you see in the picture.
Play audio and type the numbers that you hear.
Show a different picture.

Sign in

Hotmail, Xbox Live, Messenger, or msn accounts will also work.

Don't have one of the above accounts?

Signing in...
This page will automatically update after you are signed in.
If you are having problems, you can close this message and try to connect again.