Techware Labs Header

Forums have moved

See this announcement for more details, or just go directly there.

  #1  
Old 09-19-2004, 08:05 AM
JohnE JohnE is offline
Techie
 
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
Default SAIE.EXE

This afternoon a program called "Saie.exe" installed itself into the "Startup" section of my System Configuration Utility (MSCONFIG.EXE). I'm currently running Windows XP Home Edition.

I hadn't dowloaded it so I was pretty sure it was a worm or trojan of some description, so I disabled it from starting and then ran some scans using Norton Antivirus and AdAware (neither of which detected it).

I then tried several methods of removing it (i.e. the obvious things like System Restore and Add/Remove Programs) - and I also looked under Performance & Maintenance but still couldn't find any way of taking it out of my startup options. Eventually, I just removed it manually, along with its registry entries etc., which seems to have done the trick.

I then did a search on Google for "SAIE.EXE" but it didn't come up with anything. I'm just curious to know what this program was. Does anybody know?
Reply With Quote
  #2  
Old 09-19-2004, 12:09 PM
Jason425 Jason425 is offline
Lab Master Techie
 
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
Send a message via AIM to Jason425 Send a message via Yahoo to Jason425
Default

probably something bad... and it's gone now and it seems like nothing bad happened so consider yourself lucky..
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net

Reply With Quote
  #3  
Old 09-19-2004, 03:46 PM
Napster Napster is offline
Golden Techie
 
Join Date: May 2004
Location: Chicago
Posts: 442
Send a message via AIM to Napster
Default

It was most likely a giant Trojan horse, Like the Trojan of Trojans and it was the worst virus ever and the second it Extracts onto your hard drive you will only have 30 seconds until total system corruption. but of course you were quick enough to disarm and disable this virus before the 30 seconds was up..
Reply With Quote
  #4  
Old 09-19-2004, 08:50 PM
Jason425 Jason425 is offline
Lab Master Techie
 
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
Send a message via AIM to Jason425 Send a message via Yahoo to Jason425
Default

i wanna see that trojan.. that reminds me of stinky.. he took mylaptop and tried to DL some cracked version of a game and ran some exe that took over and put spyware up the wazoo in there.. 45 min later, I think i've got it cleaned up...
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net

Reply With Quote
  #5  
Old 09-20-2004, 02:17 AM
JohnE JohnE is offline
Techie
 
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
Default

Shucks. I've zapped it now, I'm afraid.... If you really want to get yourself infected (I'm sure you don't!) I was trying to check some of the Lyrics for "Mister Blue Sky" by ELO. I just typed "Mister Blue Sky" into Google and the infected site was one of the first entries. Don't know which one though - and I'm not going back to find out!! I only detected it so quickly because Zone Alarm caught it trying to access the internet.

I must admit though, I was disappointed that there wasn't a thing about it on Google. I guess it must be quite a new one. No real damage done as far as I can tell.
Reply With Quote
  #6  
Old 09-20-2004, 12:45 PM
Jason425 Jason425 is offline
Lab Master Techie
 
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
Send a message via AIM to Jason425 Send a message via Yahoo to Jason425
Default

good to hear chaps!
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net

Reply With Quote
  #7  
Old 09-25-2004, 08:12 AM
Laknet
 
Posts: n/a
Default

Hey i dont know if you guys know this but this bug trojan thing is really starting to annoy me. I got it about 2 days ago and it just keeps reapplying it self. if you check your windows system32 directory and read the saie log it gives you the jist that ht has gone in and made it so when you do a search or visit some sites eg google it reappears. It also gets into your regestry and plants it very nice seeds all through it. I have yet to get it to stop coming back. If anyone knows how to kill it for good please let me know.
Reply With Quote
  #8  
Old 09-25-2004, 10:14 AM
JohnE JohnE is offline
Techie
 
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
Default

SAIE.EXE might possibly be a trojan downloader or, more likely, you've got yourself infected with one.

A few months ago a virus called Downloader.trojan was doing the rounds but NAV can now detect and remove it.

To remove SAIE, I just did a search for SAIE in the System Registry and removed any reference to it - then I searched my C: drive for " SAIE*.* " and zapped anything I found.

However, I had to open MSCONFIG first and deselect it on the Startup options, then reboot.

After I'd successfully removed it, I did a System Restore back to a suitable date, just to be on the safe side.
Reply With Quote
  #9  
Old 09-25-2004, 10:59 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

You might also want to try HijackThis and AdAware or Spybot.
Reply With Quote
  #10  
Old 09-27-2004, 12:07 PM
arod
 
Posts: n/a
Default saie.exe

I found saie.exe on a machine as well. I also found a log that apparently was tracking web traffic on that machine as well as trying to initiate pings and bunch of other stuff. Look for a log file on that machine with same name as saie, interesting.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 08:08 PM. Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Forum style by ForumMonkeys.