Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.

Windows 7: Looks familiar? Yes! From Alureon!

09 Dec 2010   #1

Win 7 Ultimate 64-bit. SP1.
Looks familiar? Yes! From Alureon!


It's a normal day to us. We receive a new Bamital virus sample report from a customer, and we provide an analysis. Suddenly, something interesting bursts into my eyes:

What's your thought on this code fragment? At the first glance, this piece of code looks like a non-malicious call to manipulate the Windows Printer SubSystem. But if you've analyzed Alureon before, it may look familiar to you. Yes, Alureon also takes advantage of the Windows Print Subsystem to install its payload.

Now let's recall Alureon's nasty stuff:

The older Alureon installs its payload by using Windows Print Manager. It drops its malicious payload to the Print Processor directory and then calls a winspool API AddPrintProcessorA() to issue an RPC request to the Printing SubSystem, which is hosted by spoolsv.exe; the spoolsv.exe then loads the Alureon payload from the Print Processor directory:

Since the spoolsv.exe is a trusted system process, it makes Alureon difficult to detect by HIOS/Anti-virus
Looks familiar? Yes! From Alureon! - Microsoft Malware Protection Center - Site Home - TechNet Blogs

My System SpecsSystem Spec


 Looks familiar? Yes! From Alureon!

Thread Tools

Similar help and support threads
Thread Forum
Anyone Familiar with sfc /scannow?
Hi all I'm having trouble resolving this issue in Windows 7 that may (or may not) be causing my system to freeze up. When I run a scannow in an elevated prompt a get errors, so I get a Notepad log showing me what's what. The log appears to indicate that the problem is with explorer.exe ...
Performance & Maintenance
Is Anyone Familiar with ZipCloud?
I got this is an email to download ZipCloud, and it sounds good(the price is right -free_) but was just wondering if its okay to use,or just something to slow my pc down. Thanks ZipCloud :: Cloud Storage - Computer Backup and Online Storage Never mind, it started backing up my files,...
Backup and Restore
[Q] Alureon.A: Causes and removal
Recently I exchanged some data with my friend via his pendrive. A day after transferring the data, Microsoft Security Essentials caught a trojan named Alureon.A. Though MSE detected the trojan, neither could it remove it nor quarantine it. Worse was that my laptop was couldn't even stay on for even...
System Security
I've had this incredibly annoying infection for the last few weeks. I've done some searching online and don't get many clear answers about this one. It got to the point that i formatted my hdd, which was due anyway, but after a fresh install of Win 7 i still get prompts from MSE. I've gathered...
System Security
I cant get rid of this Trojan. I use MSE and even tried Mcafee 8.7i( which didnt pick it up). Help someone please...
System Security

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 15:23.

Twitter Facebook Google+

Windows 7 Forums

Seven Forums Android App Seven Forums IOS App