PDA

View Full Version : So I have a trojin named Downloader AAI


Hikari Tsukishiro
09-05-2005, 11:21 PM
I don't know what to do for this one.

Chaos Theory
09-06-2005, 04:45 AM
spybot?

I highly recommend microsoft's antispyware software as well

http://www.microsoft.com/athome/security/spyware/software/default.mspx

Chicken Little
09-06-2005, 06:30 AM
This Trojan contacts the website www.pacimedia.com (200.170.192.51) to download various adware and trojan files. It keeps listening on a random TCP port and downloads the unwanted or malicious applications at regular intervals of time. It gives enough time between each download so that previous downloaded programs can fully install, and potentially in an effort to go unnoticed (due to excessive CPU utilization when it is downloading malware and unwanted programs).

Known file names include:

* PSoft1.exe
* Ps1.exe

The various known adware/trojans downloaded by this trojan include, but are not limited to:

* Adware-aBetterintrnt
* Application Downloader-KL
* Generic Downloader.aa Trojan
* Adware-DealHelper
* Adware-WebSearch
* Adware-EliteBar
* Adware-BkdSpace
* Adware-Apropos
* Adware-PortalScan
* Application VirtualBouncer

* All of the above adware, applications, and trojans are detected by McAfee(TM).

Upon execution it creates a registry key

* HKEY_USERS\.DEFAULT\Software\P Soft1

The overall affect on the infested machine will be lots of pop-ups, many toolbars will be added to IE, keywords typed in the search area may be hijacked to show advertisements and many URLs may be dropped on desktop and added to favorites in Internet Explorer prompting to download AntiSpyware products or play casino games.

Presence of the aforementioned registry key and a process named psoft1.exe or ps1.exe in task manager.(* The name of the process may vary this is just an example)

Please note: If Adware is installed via a Downloader it may install it "cleanly" with the relevant uninstaller included for the user to terminate this Adware, although frequently this is not the case.

--------------------------

theres some info for you, most virus scanners already have a dat file that picks it up and cleans it (this particular one taken from mcafee)so updating a virus scanner and running it should pick it up. If youre knowledgeable with pcs then you can also get a fix by diff means here (http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm)

Gravity
09-06-2005, 11:20 AM
Do that system recovery thingy - the thing that Kimiko always is talking about. <.<

Zelphiel
09-06-2005, 12:48 PM
either do what cammy and fly said or try spyware doctor or adaware. those scan and fix your registry as well. also try registry mechanic (which I recommend anyway). it fixes all of your registry errors... well... all of them if you buy the software. it only fixes some of them in the free version... but it's still good.

cid
09-06-2005, 09:06 PM
Yea...and if it gets to the point where you can't do anything more about it...and it just keeps downloading trojans and viruses, malware...whatever it does, you'll prolly need to reformat your harddrive...