We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Alemod
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Windows Defender Antivirus detects and removes this threat.
Win32/Alemod is a family of data-stealing trojans. An installation of Win32/Alemod includes a trojan dropper and three files that the dropper installs: a dynamic-link library (DLL), a program that displays a Web-shortcut icon in the taskbar notification area, and a partial-uninstaller program. The trojan dropper infects the Windows system file wininet.dll in order to capture data from outgoing user web traffic. Win32/Alemod transmits the captured user data to other websites and places a hypertext link and other shortcuts to potentially malicious websites on the user desktop. Microsoft detects the infected wininet.dll file as Win32/Nsag.
Use the following free Microsoft software to detect and remove this threat:
- Microsoft Defender Antivirus for Windows 10 and Windows 8.1, or Microsoft Security Essentials for Windows 7 and Windows Vista
- Microsoft Safety Scanner
You should also run a full scan. A full scan might find hidden malware.
Get more help
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.
If you’re using Windows XP, see our Windows XP end of support page.