Malicious Software Encyclopedia: Win32/Purstiu
Published:
September 8, 2005 Win32/Purstiu is a family of Trojan downloaders that targets certain versions of Microsoft Windows. These Trojan downloaders are Internet Explorer browser helper objects (BHOs) that can download and run a file from a Web site. On This Page
Threat Overview
Aliases (Also Known As)Different antivirus vendors may be using different names to refer to this malicious software. Here are some of the names currently in use by antivirus software vendors participating in the Microsoft Virus Information Alliance (VIA):
Learn more about the
Microsoft Virus Information Alliance.
Technical Analysis
How to Prevent InfectionTake the following steps to help prevent infection on your system:
Enable a firewall on your computerUse a third-party firewall product or turn on the Microsoft Windows XP Internet Connection Firewall. To turn on the Internet Connection Firewall in Windows XP
Get the latest computer updatesUpdates help protect your computer from viruses, worms, and other threats as they are discovered. You can use the Automatic Updates feature in Microsoft Windows XP to automatically download future Microsoft security updates while your computer is on and connected to the Internet. To turn on Automatic Updates in Windows XP
Use up-to-date antivirus softwareMost antivirus software can detect and prevent infection by known malicious software. You should always run antivirus software on your computer that is updated with the latest signature files to automatically help protect you from infection. If you don't have antivirus software installed, you can get it from one of several companies. For more information, see http://www.microsoft.com/athome/security/downloads/default.mspx How to Tell If Your Computer Is InfectedWin32/Purstiu can download a file from a Web site to your computer and run the file. This can cause Windows Explorer (explorer.exe) to crash, which causes a dialog box to display, stating that such an error has occurred. A second dialog box, for the Dr. Watson program debugger, appears to ask whether you would like to send the error information to Microsoft. The Windows desktop (including the taskbar, Start button, and desktop icons) may disappear and then reappear. How to Recover from InfectionAutomatic Recovery Payload Information
|