AIMJacker


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Detection and Removal ·
· Research ·



Overview

Summary:

Sends all stored usernames and passwords to the attacker's ICQ number.

Vendor Notes:

From the doc: 'only 2.35kb compressed notifies with new icq string deletes itself ,removing any traces of where the data was sent :)' ' ill-aim jacker ver. 2.0 Coded by illwill in ASM 3/27/2002
====================================================
a 2.35kb aim pws thats sends all stored user names and passwords to you icq number
====================================================
features:
only 2.35kb compressed notifies with new icq string deletes itself ,removing any traces of where the data was sent :)
Instructions
1. extract all files from zip to a folder
2. open up editor.exe
3. select the ... to browse for server.exe
4. once server selected press read
5. change the settings to your icq #
6. compress it then send it **note will not work on aim version 4.8 or if they dont have the 'store password' option Thanks to: thelooserkiller for tons of help
===========================================================
This program comes with absolutely no warranty of any kind. Use this program solely at your risk. The author of this program will not be held responsible for any damages caused by this program.So if you fuck yer shit up dont come crying to me. :)

Alias:

Trojan.PSW.AimJaker.10, TrojanDownloader.Win32.Small.f

Category:

AOL Pest: Any password stealer, exploit, DoS attack, or ICQ hack aimed at users of AOL. ICQ is an instant messenger service from mirabilis.com, now AOL. ICQ is a favorite service among hackers, and ICQ features are built into many trojans (such as stealing user's passwords, UINs, or notifying the hacker). Users of ICQ are warned ""By using the ICQ service and software... you may be subject to various risks, including... Spoofing, eavesdropping, sniffing, spamming, breaking passwords, harassment, fraud, forgery, 'imposturing', electronic trespassing, tampering, hacking, nuking, system contamination including without limitation use of viruses, worms and Trojan horses causing unauthorized, damaging or harmful access and/or retrieval of information and data on your computer and other forms of activity that may even be considered unlawful.""

Password Capture: A variant of the Key Logger that captures passwords as they are entered or transmitted. Some password capture trojans impersonate the login prompt, asking the user to provide their password.

Variants:

  • AIMJacker 1.0
  • AIMJacker 2.0
  • Similar Pests:

    AOL Pest · Password Capture

    Origins

    Author:

    Illwill

    EMail:

    xillwillx@yahoo.com

    Programming Language:

    Assembly

    Date of Origin:

    Variants from March, 2002 to August, 2002

    Distribution

    Prevalence:

  • AIMJacker 2.0: < 0.00005%
  • More Info

    Clot Factor:

  • AIMJacker 2.0: < 1
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Countries Affected:

    In the past three months, we have received reports of AIMJacker in United States.

    Operation

    Storage Required:

  • AIMJacker 1.0: at least 49 KB
  • AIMJacker 2.0: at least 37 KB
  • ScreenShot:


    Ill-Aim Jacker 1.0



    Ill-Aim Jacker 2.0


    Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    Follow these steps to remove AIMJacker from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.
    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Research

    File Analyses:

    More Info:

  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • PestPatrol's Pest Research Center
  • Last Revised:

    April 14, 2005