We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:DOS/Alureon.F
Aliases: Alureon (Command) BOO/TDss.O (Avira) Trojan.Tdlbkfs.2 (Dr.Web) Trojan.DOS.Alureon (Ikarus) TDSS!mbr (McAfee) Troj/TdlMbr-D (Sophos)
Summary
Trojan:DOS/Alureon.F is a Master Boot Records (MBR) infected by certain variants of the Win32/Alureon rootkit family. The rootkit can infect both 32-bit and 64-bit systems.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials
- Microsoft Safety Scanner
- Microsoft Windows Malicious Software Removal Tool
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Additional recovery instructions for Trojan:DOS/Alureon.F
This virus may cause damage to the Volume Boot Record (VBR) . You will need to run the following commands using the "bootrec.exe" tool to ensure a complete repair of your computer:
bootrec /fixmbr
bootrec /fixboot
bootrec /rebuildbcd
For more details on these commands, please refer to Microsoft Security Article KB927392, with specific focus to the options "/fixmbr", "/fixboot" and "/rebuildbcd".