<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: My.yahoo  downloading trojan&#x27;s? in Security</title>
<link>http://www.dslreports.com/forum/r20909630</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 02:05:41 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 02:05:41 EDT</lastBuildDate>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20928332</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : Thanks for the suggestion and i did do a search and nothing was found. So i guess i was one of the lucky ones to not of gotten hit with this problem.<br><small>--<br>Advertising is legalized lying. - H.G. Wells<br>Pleasure in the job puts perfection in the work. - Aristotle</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20928332</guid>
<pubDate>Sun, 10 Aug 2008 11:10:40 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20927824</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : A user on another forum i visit, found this plgou SQL injection website 2days ago(i think), i did a little bit of seeing exactly what the files do<br><br>Theres 2 dif files hosted there, one on the csrss area, that file is the worse of the two, it downloads 3 more files, and tries to run a 'sl.exe', my VM currently runs on crappy vista so i couldn't investigate further, but if you were hit, you may wish to look for sl.exe(no guarentee it may change filename/delete after run)<br><br>-Brian]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20927824</guid>
<pubDate>Sun, 10 Aug 2008 07:03:40 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20926197</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : I haven't used mine in so long i was suprised to see it still there and with a new look at that. But i had no problems with my.yahoo.<br><small>--<br>Advertising is legalized lying. - H.G. Wells<br>Pleasure in the job puts perfection in the work. - Aristotle</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20926197?c=1336823&ret=L2ZvcnVtL3IyMDkwOTYzMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="164956 bytes" WIDTH=600 HEIGHT=402 SRC="/r0/download/1336823.thumb600~faf45ca4b9f1e68f8e0251b17f9c1a9a/avast.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20926197</guid>
<pubDate>Sat, 09 Aug 2008 18:47:55 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20925638</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Another article:<br><br>My.yahoo.com Hosts Trojans - Apparently driven by techbargains.com<br>&raquo;<A HREF="http://news.softpedia.com/news/My-yahoo-com-Hosts-Trojans-91662.shtml" >news.softpedia.com/news/My-yahoo&middot;&middot;&middot;62.shtml</A><br><div class="bquote"> The msyahoo.exe file, downloaded as rondll32.exe, installed hidden programs and commands that made some resources in users' computers available to hijackers.</div>sans.org notes that these files, msyahoo.exe and rondll32.exe surfaced in their current SQL injection analysis, which may be linked to the techbargains.com exploit:<br><br>More SQL Injections - very active right now<br>&raquo;<A HREF="http://isc.sans.org/diary.html?storyid=4844" >isc.sans.org/diary.html?storyid=4844</A><br><br>EDIT: In the above diary, scroll down to the "yahoo.htm" analysis. The script code is the same as the code for the plgou.com/csrss/yahoo.htm site you mentioned in your post.<br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20925638</guid>
<pubDate>Sat, 09 Aug 2008 16:07:29 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20921598</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : As japiscan00 above said, the trojans were as a result of an<br>attack on Techbargains. Anyone who had their RSS feed in <br>their MyYahoo page would have gotten the virus warnings from<br>their AV (or the trojan if it wasn't detected). Sandi <br>Hardmeier's Spyware Sucks blog has a writeup:<br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/08/1643844.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;844.aspx</A><br><br>This topic is linked there.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20921598</guid>
<pubDate>Fri, 08 Aug 2008 19:06:40 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20915642</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :    very believable scenario. How about the name of that malicious script "fuckjp" (as in, Fuck Japan), they're getting Japan back for WWII? No wonder Japan attacked them! I feel like attacking them myself!! <br><br>   I still haven't gotten Outlook Express or *any* browswer working again, so they must have hosed some of my Internet access files before I killed their script. I've re-applied XP sp2, but this is "Home" edition, so if want to re-install XP, I've got to obliterate my HD. Oh why didn't I switch to Linux like my mother told me to?...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20915642</guid>
<pubDate>Thu, 07 Aug 2008 17:16:20 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20915592</link>
<description><![CDATA[<A HREF="/useremail/u/526806"><b>louist</b></A> : Yes multiple problems yesterday and today. Our AV product  is intercepting the trojan and disabling it.  In some cases this action also disable IE.  <br><br>When I shut and restart IE the problem corrects, but if you visit "My.yahoo" again, it happens again every time. Easily replicable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20915592</guid>
<pubDate>Thu, 07 Aug 2008 17:06:43 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20915123</link>
<description><![CDATA[<A HREF="/useremail/u/807557"><b>la_pepe59</b></A> : I found an interesting article regarding Iframe's on CA's website.  Here is a link as to what was happening and will probably continue to happen for at least a bit anyway.<br><br>http://community.ca.com/blogs/securityadvisor/archive/2008/05/28/compromised-websites-a-real-danger-for-internet-users.aspx]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20915123</guid>
<pubDate>Thu, 07 Aug 2008 15:48:36 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20915032</link>
<description><![CDATA[<A HREF="/useremail/u/1343158"><b>Graystoke</b></A> : <div class="bquote"><small>said by rudee :</small><br><br>Hello,<br><br>One thing I've noticed about my.yahoo.com since I started using it is that it actually goes to cm.my.yahoo.com; that's happening with Yahoo's explicit permission. They've farmed my yahoo out to Mainland Chinese programmers (not surprising since the CEO is chinese) and now that anally retentive Chinese premier has put gov't programmers on "payback" detail to western journalists for stirring up trouble... us poor my.yahoo.com saps got taken along for the ride... just a theory. </div>Is that what the "cm" stands for?  I always wondered what that stood for.  Actually, I only saw that when the new My.Yahoo page was in beta.  I don't see the "cm" anymore.<br><br>Back on subject.  My.Yahoo working ok here with Firefox and IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20915032</guid>
<pubDate>Thu, 07 Aug 2008 15:34:01 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20914662</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Well if (& assuming) this type of code is being injected into Yahoo (my.yahoo.com) web pages, isn't that going to be a vulnerability that exists on Yahoo's end (on their servers/softwares)?<br><br>Or could it be caused by code the end user placed into their page?<br><br>I gather if you have this patch installed, you're likely to be less vulnerable.<br><br>&raquo;<A HREF="http://www.microsoft.com/technet/security/Bulletin/MS07-021.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;021.mspx</A><br><br>Further, as it appears to use vbscript/ActiveX, using a Mozilla browser would render the page ineffective.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20914662</guid>
<pubDate>Thu, 07 Aug 2008 14:31:19 EDT</pubDate>
</item>

<item>
<title>Re: openDNS</title>
<link>http://www.dslreports.com/forum/remark,20914633</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Good to know about and I'll use it, but I'm using a router at home and the problem only exists on the PC that got redirected to the chinese mainland web site. I changed over my router to openDNS and my.yahoo.com started to load, whereas before I was getting "web site could not be loaded". Not sure if that's because yahoo has fixed it in the interim, but they better mention something about this or I'm going to twitter to blog about it ;-).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20914633</guid>
<pubDate>Thu, 07 Aug 2008 14:27:03 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20914555</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I started having the same problem at around the same time.  I found that an RSS feed, that I had setup on my Yahoo home page, may have been causing the problem (i.e., techbargains.com).<br><br>when I tried to go to the site directly, I found:<br><br>   Techbargains.com is undergoing maintenance right now.<br><br>   Come back soon!<br><br>I deleted the RSS feed from my Yahoo home page, the problem went away (no more links to plgou.com) and no more McAfee warnings of trojans.<br><br>I am thinking that maybe the site got hacked, and they are trying to fix it.  This was one of my favorite feeds, hope they fix it. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20914555</guid>
<pubDate>Thu, 07 Aug 2008 14:16:46 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20914427</link>
<description><![CDATA[<A HREF="/useremail/u/806325"><b>VerdeDude</b></A> : Could be possible DNS poisoning, which takes you to a malicious site.  <br>     Try using open DNS (www.opendns.com) and see if it fixes the problem.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20914427</guid>
<pubDate>Thu, 07 Aug 2008 13:51:36 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20914134</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hello,<br><br>   Yes, I have seen these exact symptoms. In addition, I saw that IE wanted to load the chinese character set and some kind of popup window appeared with a chinese looking name on it. It's either chinese dissidents or chinese gov't behind it. After deleting the previously mentioned files in system32, The b**tard hosed something to do with my Internet access. I can ping everything, but IE and Outlook Express won't work. I installed Firefox and that wouldn't work either. I haven't done anything else, but it looks like I'm going to have to run XP repair. I'm guessing it replaced one the Microsoft dll's related to http, probably a redirector of some kind. Everything works from my other computer so that's confirmed. <br><br>   One thing I've noticed about my.yahoo.com since I started using it is that it actually goes to cm.my.yahoo.com; that's happening with Yahoo's explicit permission. They've farmed my yahoo out to Mainland Chinese programmers (not surprising since the CEO is chinese) and now that anally retentive Chinese premier has put gov't programmers on "payback" detail to western journalists for stirring up trouble... us poor my.yahoo.com saps got taken along for the ride... just a theory. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20914134</guid>
<pubDate>Thu, 07 Aug 2008 13:01:03 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20909630</link>
<description><![CDATA[<A HREF="/useremail/u/408869"><b>skyroket</b></A> : I haven't used that in quite awhile, but can't you put "unsupported" modules on your page?  Maybe someone's IFRAME or some module is redirecting to some bad site.  I'd remove all questionable modules and start over with your page customization.<br><br>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20909630</guid>
<pubDate>Wed, 06 Aug 2008 16:48:04 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20909231</link>
<description><![CDATA[<A HREF="/useremail/u/479009"><b>Le Boule</b></A> : &raquo;<A HREF="http://www.pcqanda.com/dc/dcboard.php?az=show_topic&forum=2&topic_id=488178&mode=full&page=" >www.pcqanda.com/dc/dcboard.php?a&middot;&middot;&middot;ll&page=</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20909231</guid>
<pubDate>Wed, 06 Aug 2008 15:50:53 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908914</link>
<description><![CDATA[<A HREF="/useremail/u/767055"><b>heels_fan</b></A> : FF 3.0.1<br><br>No suspect activity]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908914</guid>
<pubDate>Wed, 06 Aug 2008 14:58:43 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908909</link>
<description><![CDATA[<A HREF="/useremail/u/881809"><b>MagMan</b></A> : I tested mine also and everything is ok.<br><br>I rarely use it though. :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908909</guid>
<pubDate>Wed, 06 Aug 2008 14:57:09 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908859</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : I do not doubt what you are saying I just answered your question on how MyYahoo worked for me.<br><br>Other members that use MyYahoo will no doubt chime in and let you know their results.<br><small>--<br>"Living on Earth is expensive, but it does include a free trip around the sun".</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908859</guid>
<pubDate>Wed, 06 Aug 2008 14:48:52 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908763</link>
<description><![CDATA[<A HREF="/useremail/u/807557"><b>la_pepe59</b></A> : Here is a link to another thread regarding this<br>&raquo;<A HREF="http://answers.yahoo.com/question/index?qid=20080806083409AA3SNrG" >answers.yahoo.com/question/index&middot;&middot;&middot;9AA3SNrG</A><br><br>I am using IE7 fully patched but haven't been back there lately as I am trying to remove the nasties from my machine.  When launching IE normally it creates subs called sss.exe, beauty.exe and fengxing.exe that I see in process explorer.  Under limited user, those don't launch.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908763</guid>
<pubDate>Wed, 06 Aug 2008 14:32:11 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908611</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : Just tested MyYahoo and it is working fine on Fx v3.0.2pre.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908611</guid>
<pubDate>Wed, 06 Aug 2008 14:05:32 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908600</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : MyYahoo is the personalized page yahoo users can create if they have an account.<br><br>Email, weather, personalized news, etc.. The user puts it together by selecting modules and colors. <br><small>--<br>"Living on Earth is expensive, but it does include a free trip around the sun".</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908600</guid>
<pubDate>Wed, 06 Aug 2008 14:04:10 EDT</pubDate>
</item>

<item>
<title>Re: My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908564</link>
<description><![CDATA[<A HREF="/useremail/u/530781"><b>Rungel</b></A> : What is My.yahoo? Is it part of there messenger IM service?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908564</guid>
<pubDate>Wed, 06 Aug 2008 13:55:40 EDT</pubDate>
</item>

<item>
<title>My.yahoo  downloading trojan&#x27;s?</title>
<link>http://www.dslreports.com/forum/remark,20908087</link>
<description><![CDATA[<A HREF="/useremail/u/807557"><b>la_pepe59</b></A> : It appears to have started today but going to my yahoo page is linking to plgou.com/csrss/yahoo.htm and trying to download some trojans.  I noticed another thread on answers.com where another person was having the same issue and it just started today.  <br><br>Anyone else seen this?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20908087</guid>
<pubDate>Wed, 06 Aug 2008 12:33:37 EDT</pubDate>
</item>

</channel>
</rss>
