<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-749487935022983786</id><updated>2011-04-21T21:12:05.308-07:00</updated><title type='text'>Yahoo! Counter Starts Trojan Advice</title><subtitle type='html'>an approach to dealing with this nasty trojan</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://vbadvice.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/749487935022983786/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://vbadvice.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>JT</name><uri>http://www.blogger.com/profile/14445063632273715340</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-749487935022983786.post-2024745362959366337</id><published>2008-12-26T04:59:00.000-08:00</published><updated>2008-12-26T05:06:36.417-08:00</updated><title type='text'>Web Browser Hijack by this same trojan</title><content type='html'>The previous post deals with the Yahoo! Counter Starts trojan in your forum database files. This post is about associated malware that the trojan drops into your local computer.&lt;br /&gt;&lt;br /&gt;The trojan drops a file called:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;sysaudio.sys&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;into your &lt;span style="font-weight:bold;"&gt;WINDOWS/system32&lt;/span&gt; folder.&lt;br /&gt;&lt;br /&gt;This causes the malware to hijack your web browser.&lt;br /&gt;So when you do a search in Google, you do not see &lt;br /&gt;the normal Google results, but a set of search engines&lt;br /&gt;and other sites, such as:&lt;br /&gt;moxiesearch.com&lt;br /&gt;findstuff.com&lt;br /&gt;and similar sites.&lt;br /&gt;&lt;br /&gt;Create a new folder, &lt;br /&gt;then move the sysaudio.sys file &lt;br /&gt;from the system32 folder to the new folder,&lt;br /&gt;and rename the file.&lt;br /&gt;Next, reboot your computer.&lt;br /&gt;This should solve the problem of the web browser &lt;br /&gt;redirection (hijacking).&lt;br /&gt;&lt;br /&gt;HOWEVER, there is a normal sysaudio.sys file &lt;br /&gt;that you should NOT delete, move, or rename&lt;br /&gt;in the &lt;span style="font-weight:bold;"&gt;WINDOWS/system32/drivers&lt;/span&gt; folder&lt;br /&gt;Do NOT mess with that file; it is a normal file &lt;br /&gt;on Windows computers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/749487935022983786-2024745362959366337?l=vbadvice.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://vbadvice.blogspot.com/feeds/2024745362959366337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://vbadvice.blogspot.com/2008/12/web-browser-hijack-by-this-same-trojan.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/749487935022983786/posts/default/2024745362959366337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/749487935022983786/posts/default/2024745362959366337'/><link rel='alternate' type='text/html' href='http://vbadvice.blogspot.com/2008/12/web-browser-hijack-by-this-same-trojan.html' title='Web Browser Hijack by this same trojan'/><author><name>JT</name><uri>http://www.blogger.com/profile/14445063632273715340</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-749487935022983786.post-7364515093701784206</id><published>2008-12-23T18:08:00.000-08:00</published><updated>2008-12-24T04:27:00.826-08:00</updated><title type='text'>Yahoo! Counter starts trojan</title><content type='html'>I found a relatively simple fix for the 'Yahoo! Counter starts' trojan that affects VBulletin and other forum software. Here's what I did:&lt;br /&gt;&lt;br /&gt;I did a backup of the SQL database in VBulletin:&lt;br /&gt;I went into the Admin Panel; clicked Maintenance, database backup.&lt;br /&gt;At the bottom of that page, I went to the section that says&lt;br /&gt;Backup database to a file on the server. Then I did the following:&lt;br /&gt;&lt;br /&gt;1. made new directory within the /forum/ folder called /backup&lt;br /&gt;2. made new directory worldwritable&lt;br /&gt;chmod 777 backup&lt;br /&gt;3. entered location for backupfile in Admin panel:&lt;br /&gt;./backup/forumbackup-year-month-day.sql&lt;br /&gt;4. Clicked save&lt;br /&gt;&lt;br /&gt;Then I went into site by FTP and downloaded the SQL backup file,&lt;br /&gt;and deleted the file from the site, and deleted the folder.&lt;br /&gt;&lt;br /&gt;Then I searched the backed up SQL file for 'Yahoo! Counter' and found&lt;br /&gt;two sections of code that had been inserted into the database by the trojan.&lt;br /&gt;&lt;br /&gt;I found the code by doing a backup of the entire database with vBulletin,&lt;br /&gt;then searching the SQL file generated by that back up.&lt;br /&gt;Both sections of code have 'Yahoo! Counter' in them.&lt;br /&gt;&lt;br /&gt;Then I logged into my website hosting company's control panel, and used&lt;br /&gt;PHPmyadmin to go into the mySQL database (I have IXwebhosting), and&lt;br /&gt;I edited the affected tables (the names of the tables were found from the&lt;br /&gt;previous search of the backed up SQL file).&lt;br /&gt;&lt;br /&gt;datastore options&lt;br /&gt;[datastore is the name of a table in the database,&lt;br /&gt;and options is a section within that table]&lt;br /&gt;&lt;br /&gt;and likewise with:&lt;br /&gt;&lt;br /&gt;setting description&lt;br /&gt;&lt;br /&gt;The section of bad code in datastore begins with:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;1108:\"\" /&gt;&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;and then continues on to include:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;Yahoo! Counter starts&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;and then continues on to end with: &lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;name=\"yahoo\" content=\"count\"&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;and the repaired code in 'datastore options' should include:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;;s:11:\"description\";s:0:\"\";s:12:\"useforumjump\";i:1&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;The bad code had changed&lt;br /&gt;;s:0:&lt;br /&gt;to&lt;br /&gt;;s:1108:&lt;br /&gt;and then added the malicious code after the 1108. So after deleting the bad section of code, I made sure the repaired code had the zero and not the 1108&lt;br /&gt;&lt;br /&gt;The section of bad code in 'setting description' was easier to fix.&lt;br /&gt;This good code:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;INSERT INTO setting VALUES('description', 'general', '', &lt;br /&gt;'This is a discussion forum powered by vBulletin. To find out about vBulletin, go to http://www.vbulletin.com/ .',&lt;br /&gt; '', '20', '0', '1', 'free', 'vbulletin', '', '0');&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;had been replaced by a long section of code that included the text:&lt;br /&gt;Yahoo! Counter starts&lt;br /&gt;&lt;br /&gt;I replaced that long section of code with the text:&lt;br /&gt;&lt;PRE&gt;&lt;br /&gt;This is a discussion forum powered by vBulletin. To find out about vBulletin, go to http://www.vbulletin.com/ .&lt;br /&gt;&lt;/PRE&gt;&lt;br /&gt;This worked for me. I don't know if it will work for anyone else.&lt;br /&gt;Proceed similarly at your own risk.&lt;br /&gt;Good luck!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/749487935022983786-7364515093701784206?l=vbadvice.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://vbadvice.blogspot.com/feeds/7364515093701784206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://vbadvice.blogspot.com/2008/12/yahoo-counter-starts-trojan.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/749487935022983786/posts/default/7364515093701784206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/749487935022983786/posts/default/7364515093701784206'/><link rel='alternate' type='text/html' href='http://vbadvice.blogspot.com/2008/12/yahoo-counter-starts-trojan.html' title='Yahoo! Counter starts trojan'/><author><name>JT</name><uri>http://www.blogger.com/profile/14445063632273715340</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
