
09-19-2004, 08:05 AM
|
Techie
|
|
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
|
|
SAIE.EXE
This afternoon a program called "Saie.exe" installed itself into the "Startup" section of my System Configuration Utility (MSCONFIG.EXE). I'm currently running Windows XP Home Edition.
I hadn't dowloaded it so I was pretty sure it was a worm or trojan of some description, so I disabled it from starting and then ran some scans using Norton Antivirus and AdAware (neither of which detected it).
I then tried several methods of removing it (i.e. the obvious things like System Restore and Add/Remove Programs) - and I also looked under Performance & Maintenance but still couldn't find any way of taking it out of my startup options. Eventually, I just removed it manually, along with its registry entries etc., which seems to have done the trick.
I then did a search on Google for "SAIE.EXE" but it didn't come up with anything. I'm just curious to know what this program was. Does anybody know?
|

09-19-2004, 12:09 PM
|
Lab Master Techie
|
|
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
|
|
probably something bad... and it's gone now and it seems like nothing bad happened so consider yourself lucky.. 
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net
|

09-19-2004, 03:46 PM
|
Golden Techie
|
|
Join Date: May 2004
Location: Chicago
Posts: 442
|
|
It was most likely a giant Trojan horse, Like the Trojan of Trojans and it was the worst virus ever and the second it Extracts onto your hard drive you will only have 30 seconds until total system corruption. but of course you were quick enough to disarm and disable this virus before the 30 seconds was up..
|

09-19-2004, 08:50 PM
|
Lab Master Techie
|
|
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
|
|
 i wanna see that trojan.. that reminds me of stinky.. he took mylaptop and tried to DL some cracked version of a game and ran some exe that took over and put spyware up the wazoo in there.. 45 min later, I think i've got it cleaned up...
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net
|

09-20-2004, 02:17 AM
|
Techie
|
|
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
|
|
Shucks. I've zapped it now, I'm afraid.... If you really want to get yourself infected (I'm sure you don't!) I was trying to check some of the Lyrics for "Mister Blue Sky" by ELO. I just typed "Mister Blue Sky" into Google and the infected site was one of the first entries. Don't know which one though - and I'm not going back to find out!! I only detected it so quickly because Zone Alarm caught it trying to access the internet.
I must admit though, I was disappointed that there wasn't a thing about it on Google. I guess it must be quite a new one. No real damage done as far as I can tell. 
|

09-20-2004, 12:45 PM
|
Lab Master Techie
|
|
Join Date: Sep 2002
Location: The Matrix
Posts: 7,353
|
|
good to hear chaps!
__________________
Dell Inspiron 1420 in Midnight Blue - Intel Core2Duo T7300 2.0GHZ/4MB - 2GB Ram - Nvidia 8400 GS 128mb - DVD/RW - 160GB 7200RPM - 14.1" Antiglare - Intel 4965AGN - Bluetooth 2.0 - 2MP Webcam - Vista Home Premium
2005 Mazda3i in Strato Blue
http://www.jasondsmith.net
|

09-25-2004, 08:12 AM
|
|
Hey i dont know if you guys know this but this bug trojan thing is really starting to annoy me. I got it about 2 days ago and it just keeps reapplying it self. if you check your windows system32 directory and read the saie log it gives you the jist that ht has gone in and made it so when you do a search or visit some sites eg google it reappears. It also gets into your regestry and plants it very nice seeds all through it. I have yet to get it to stop coming back. If anyone knows how to kill it for good please let me know.
|

09-25-2004, 10:14 AM
|
Techie
|
|
Join Date: Oct 2002
Location: Manchester, England
Posts: 116
|
|
SAIE.EXE might possibly be a trojan downloader or, more likely, you've got yourself infected with one.
A few months ago a virus called Downloader.trojan was doing the rounds but NAV can now detect and remove it.
To remove SAIE, I just did a search for SAIE in the System Registry and removed any reference to it - then I searched my C: drive for " SAIE*.* " and zapped anything I found.
However, I had to open MSCONFIG first and deselect it on the Startup options, then reboot.
After I'd successfully removed it, I did a System Restore back to a suitable date, just to be on the safe side.
|

09-25-2004, 10:59 PM
|
 |
Super Moderator
|
|
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
|
|
You might also want to try HijackThis and AdAware or Spybot.
|

09-27-2004, 12:07 PM
|
|
saie.exe
I found saie.exe on a machine as well. I also found a log that apparently was tracking web traffic on that machine as well as trying to initiate pings and bunch of other stuff. Look for a log file on that machine with same name as saie, interesting.
|
Thread Tools |
Search this Thread |
|
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 04:33 PM.
Powered by vBulletin® Version 3.6.5 Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
|