Rootkit activity Using the driver "UNKNOWN" the Backdoor controls loading executable images into a memory by installing the Load image notifier.Using the driver ROOTKITPATH the Backdoor intercepts DriverStartIO in a miniport

Recovering from this situation may require measures beyond removing the trojan itself from the computer. To detect and remove this threat and other malicious software that may be installed in File activity The process %original file name%.exe:860 makes changes in the file system.The Backdoor creates and/or writes to the following file(s): %Documents and Settings%\%current user%\Local Settings\Temp\nss3.tmp\4IR.exe (1856 bytes)%Documents and Settings%\%current user%\Local The threat may also make changes to your computer that makes it difficult for you to download, install or update your virus protection, whether you have a complete antivirus such as From the affected computer, boot from the USB or CD you created in step 4.Note: You may need to set the boot order in the BIOS to do this.

In 64-bit Windows systems, Trojan:Win32/Alureon!gen.AD writes all the file components directly into the encrypted virtual file system (VFS) and attempts to directly modify the MBR: bckfg.tmp cfg.ini cmd.dll cmd64.dll drv32 drv64 ldr16 ldr32

Redirects access to certain websites Trojan:Win32/Alureon.gen!AD is capable of redirecting access requests for certain websites, which can include online financial institutions, to a destination specified by an attacker.

Collected information is also sent to a remote server. This worm looks for vulnerable machines on the network by scanning for random TCP/IP addresses on port 135.