I was really concerned about what Downloader.Age was so I posted it here. What is it? and How to get rid of it when you get it on your system. AVG Anti-spyware detects it as: C:\Windows\system32\tcbllxak.dll → Downloader.Age.
Hi flygirl,
If it is this one, here is what it does:
Troj/Banloa-AGE is a downloading Trojan for the Windows platform.
The Trojan attempts to download a files from a remote website to \csrs.scr and then execute them
Troj/Banloa-AGE temporarily downloads files to \Update before moving them.
At the time of writing csrs.scr was detected as Troj/Banker-CSW.
The Trojan displays an image pretending to be the default Windows image viewer with the title “Foto - Visualizador de Imagem e Fax do Windows” and the content “Visualizacao nao Disponivel”.
polonus
Hi flygirl,
Trojan Downloader (generic description)Trojan downloader is usually a standalone program that attempts to hiddenly download and run other files from remote web and ftp sites. Usually trojan downloaders download different trojans and backdoors and activate them on an affected system without user’s approval. Trojan downloader, when run, usually installs itself to system and waits until Internet connection becomes available. After that it attempts to connect to a web or ftp site, download specific file or files and run them.
Most famous trojan downloaders: Aphex, Dlder, Small, WebDL.
Disinfection
Adware/Spyware Issues
Very often on-line advertisment companies use trojan droppers to hiddenly drop their adware/spyware components or downloaders to users’ computers. That is why it is recommended to scan an affected computer with a spyware remover…
http://www.f-secure.com/v-descs/trojdown.shtml
Trusted spyware removers include AVG Anti-Spyware, a-Squared, Spybot Search & Destroy, Ad-Aware, SuperAntiSpyware, Spyware Terminator (all of which have free versions for the home user) and Webroot SpySweeper, Spyware Doctor and Sunblet Counterspy which you have to pay for.
If avast doesn’t detect it, send the sample to virus@avast.com zipped and password protected with password in email body and undetected malware in the subject. Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest.
avast can then analyse it and hopefully update the VPS signatures.