Skip to main content

Trojan.AOL.Buddy

Classification

Category:

Malware

Aliases:

  • Trojan.AOL.Buddy
  • W95/PennyTools.Trojan
  • PennyTools
  • Buddy

Summary

The 'W95/PennyTools.Trojan' or 'Trojan.Aol.Buddy' is an AOL password stealing trojan. Three versions are currently known (by May 1999). One version was spread inside MS Word document advertising access to AOL for free. If a user clicks on AOL logo in the document his system becomes infected. Another version is spread in another word document that has only setup icon.

Removal

Technical Details

This trojan uses a tricky way of installing itself to system. It uses 5 different ways at the same time to make disinfection more difficult:

1. Through Registry by modifying RUN key to launch C:\COMMAND.EXE

hidden file which is a trojan's body

2. Through SYSTEM.INI by adding a screensaver reference routine

to C:\Windows\System\WINSAVER.EXE - the system will become infected when screen saver starts.

3. Through WIN.INI - by adding to execution of C:\America Online

4.0\BUDDYLIST.EXE hidden file to LOAD= string with more than 80 spaces in front of line to hide it

4. Again through WIN.INI - by adding to execution of

C:\Windows\System\NortonAntiVir\REGISTRYREMINDER.EXE hidden file to RUN= string

5. Through Windows startup directory - by placing AIM

REMINDER.EXE file in \Windows\Start Menu\Programs\Startup\ folder.

Also a DLL is created in Windows\System folder with the name VCLCNTL.DLL but it contains some text data for the trojan, not DLL code. When Windows is started the trojan is also started (one of steps 1-5) and remains active during all Windows session. It sends user's AOL login and password as email to qware4019@hotmail.com, ha015312@hotmail.com or liighthack@yahoo.com addresses (depending on trojan version).

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.