INTERACT FORUM

More => Old Versions => Media Center 11 (Development Ended) => Topic started by: Shelly on January 18, 2003, 06:47:51 am

Title: Ashley 1.1.0 RAT
Post by: Shelly on January 18, 2003, 06:47:51 am
Pest Control just found 25 incidents of Ahley RAT in the J River\Media Jukebox\Data\Thumbnails folder.  

The Pest Control Website describes a RAT as follows:  "A Remote Administration Tool, or RAT, is a Trojan that when run, provides an attacker with the capability of remotely controlling a machine via a "client" in the attacker's machine, and a "server" in the victim's machine."

Would I have picked these up with downloaded coverart files?  Is there anything else that I should check for in terms of system vulnarabilities or compromises?  How paranoid should I be??? :o

TIA
Shelly
Title: Re: Ashley 1.1.0 RAT
Post by: JimH on January 18, 2003, 06:50:01 am
I don't know specifically what the problem is, but virus checkers, etc. are often mistaken.  Do they have web info on this problem?  If you have a name of a suspicious file, try a google search.
Title: Re: Ashley 1.1.0 RAT
Post by: Shelly on January 18, 2003, 06:56:22 am
The description of Ashley 1.1.0 is here:

http://pestpatrol.com/pestinfo/a/ashley.asp
Title: Re: Ashley 1.1.0 RAT
Post by: zevele10 on January 18, 2003, 02:47:28 pm
not sure ,but hard to think you get it with sleeves.
do you have any other downloads in the MJ folder?
Like songs downloaded from a p2p -kazaa?
did you check in witch Mj folder the virus is?
Title: Re: Ashley 1.1.0 RAT
Post by: Shelly on January 18, 2003, 04:40:13 pm
Zevele,

Quote
do you have any other downloads in the MJ folder?
Like songs downloaded from a p2p -kazaa?
did you check in witch Mj folder the virus is?

Ashely was found only in the internal artwork files within the MJ thumbnails folder.  Interestingly, the corresponding external artwork files are trojan free.  The only place I've downloaded artwork from besides Walmart, Buy.com, Amazon, etc. is from some of the binary newsgroups.  

Shelly
Title: Re: Ashley 1.1.0 RAT
Post by: nila on January 18, 2003, 04:43:14 pm
Binary News Groups often have viruses.

Having said that, I've never heard of a virus with a .jpg, .bmp or .gif extension which is what it would need to be to be an image?
Title: Re: Ashley 1.1.0 RAT
Post by: Shelly on January 18, 2003, 06:02:03 pm
Nila,

I checked the deleted files again and they were the thumbnails from one cd cover that was downloaded from either Wallmart or Buy.com and the external artwork (jpg) file is not infected.  

Shelly