Other versions: .ay
| Detection added |
Feb 28 2008 |
| Update released |
Feb 28 2008 21:35 GMT |
| Description added |
Jan 27 2009 |
This Trojan downloads other programs via the Internet and launches them for
execution on the victim machine without the user’s knowledge or consent.
It is a Windows PE EXE file. It is 20480 bytes in size. It is not packed in
any way. It is written in C++.
Once launched, the Trojan downloads a file from the following URL:
http://www.yahoo*****.com/image/logo.jpg?queryid=70427
This file is saved to the Internet Explorer cache. The file is then launched
for execution and deleted.
At the time of writing, the link was not active.
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Use Task
Manager to terminate the Trojan process.
- Delete the original Trojan file (the location will depend on how the program
originally penetrated the victim machine).
- Delete all files from %Temporary Internet Files%.
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).