 mysec Premium join:2005-11-29
3 edits | reply to la_pepe59 Re: My.yahoo downloading trojan's?
Another article:
My.yahoo.com Hosts Trojans - Apparently driven by techbargains.com »news.softpedia.com/news/My-yahoo···62.shtml
The msyahoo.exe file, downloaded as rondll32.exe, installed hidden programs and commands that made some resources in users' computers available to hijackers. sans.org notes that these files, msyahoo.exe and rondll32.exe surfaced in their current SQL injection analysis, which may be linked to the techbargains.com exploit:
More SQL Injections - very active right now »isc.sans.org/diary.html?storyid=4844
EDIT: In the above diary, scroll down to the "yahoo.htm" analysis. The script code is the same as the code for the plgou.com/csrss/yahoo.htm site you mentioned in your post.
|
|
  MarkAW Barry White or lil bratt Premium join:2001-08-27 Canada
·Bell Sympatico
·Cogeco Cable
1 edit | reply to la_pepe59 I haven't used mine in so long i was suprised to see it still there and with a new look at that. But i had no problems with my.yahoo. -- Advertising is legalized lying. - H.G. Wells Pleasure in the job puts perfection in the work. - Aristotle |
|
  Kayrac Premium join:2001-09-29 Rochester, NH
| A user on another forum i visit, found this plgou SQL injection website 2days ago(i think), i did a little bit of seeing exactly what the files do
Theres 2 dif files hosted there, one on the csrss area, that file is the worse of the two, it downloads 3 more files, and tries to run a 'sl.exe', my VM currently runs on crappy vista so i couldn't investigate further, but if you were hit, you may wish to look for sl.exe(no guarentee it may change filename/delete after run)
-Brian |
|
  MarkAW Barry White or lil bratt Premium join:2001-08-27 Canada
·Bell Sympatico
·Cogeco Cable
| Thanks for the suggestion and i did do a search and nothing was found. So i guess i was one of the lucky ones to not of gotten hit with this problem. -- Advertising is legalized lying. - H.G. Wells Pleasure in the job puts perfection in the work. - Aristotle |
|