downloads.aaa1screensavers.com ??

Discussion in 'Port Explorer' started by morph1, Apr 29, 2005.

Thread Status:
Not open for further replies.
  1. morph1

    morph1 Registered Member

    Joined:
    Jan 31, 2005
    Posts:
    3
    I don't know about this one ! I can't find any site or reference to this anywhere. Possibly it may have something to do with ZoneAlarm but there are still instances of it if ZAP is shut down.
    Anyone got any idea what it's about ?
     

    Attached Files:

    • aaa1.jpg
      aaa1.jpg
      File size:
      48.8 KB
      Views:
      977
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,919
    Location:
    Texas
  3. FanJ

    FanJ Guest

    Hi,

    Connecting to aaa1screensavers looks suspicious !

    I would advice to scan your system with AV/AT and anti-spyware programs.
    Maybe a scan with HijackThis is needed, but the Wilders-board doesn't do them anymore.

    BTW: aaa1screensavers is listed in IE-SPYAD from Eric Howes.
     
  4. no13

    no13 Retired Major Resident Nutcase

    Joined:
    Sep 28, 2004
    Posts:
    1,327
    Location:
    Wouldn't YOU like to know?
    If I remember correctly, it's a site that gives you trojans bundled witj screensavers... have you downloaded new screensavers?

    BTW ::: add it to your 'hosts' file and you can be sure that no program is connecting to it from your PC, even if they try to.
    Then you can run scans on your PC to see what is wrong in peace.
     
  5. Clive T

    Clive T Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    189
    Location:
    Kent, UK
    No13. You're right. I downloaded a "free" screensaver from there a little while ago and NOD32 picked up a trojan in the download immediately.

    Avoid the site.
     
  6. crkit1

    crkit1 Registered Member

    Joined:
    Aug 31, 2002
    Posts:
    93
    Location:
    Florida
  7. nick s

    nick s Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    1,430
    Hi crkit1,

    The legitimate Lavasoft Ad-Aware executable is Ad-Aware.exe, not Adaware.exe.

    Nick
     
  8. crkit1

    crkit1 Registered Member

    Joined:
    Aug 31, 2002
    Posts:
    93
    Location:
    Florida
    So...if I see adaware.exe in my programs list, I should get rid of it?
     
  9. nick s

    nick s Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    1,430
    Yes. It's a common practice to distribute malware executables with names similar to legitimate apps.

    Nick
     
  10. Shiva42

    Shiva42 Guest

    I just discovered a similar "problem" on my computer and have figured it out.
    I was using netstat -ab and Firefox instead of Port Explorer and ZoneAlarm, but it's the same thing. Your two processes (both from ZoneAlarm) are actually just connecting to your local machine normally, not to downloads.aaa1screensavers.com.

    I use a host file (in C:\windows\system32\drivers\etc) with a list of "bad" sites set to 127.0.0.1 so my browsers and other applications won't actually go to the sites. I am assuming you do the same. The copy I have did not have the required entry of

    127.0.0.1 localhost

    at the top of the file. The first entry is downloads.aaa1screensavers.com
    The application is accessing the localhost (your machine) using 127.0.0.1 and when Port Explorer did a lookup on the address it picked the first matching line one out of your hosts file (I was using netstat -ab, but it's the same principle). I commented out the aaa1screensavers lines and reran the netstat command, and the site reported was abcsearch.com (the next in the list). When I removed the comments and added the line above to the top of my hosts file (like it is supposed to be), netstat returned the correct information.
     
  11. rshoT

    rshoT Guest

    yea aaa1screansavers is deffinetly a virus that will screw you up hardcore in the long run, i suggest getting an anti-virus tool that acctually detects it and then delete
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.