<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-35484726</id><updated>2011-04-21T19:25:11.701-07:00</updated><title type='text'>Words I can say I own...</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sajinspeaks.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35484726/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sajinspeaks.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sajin Kokkad</name><uri>http://www.blogger.com/profile/08612657538924609656</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-35484726.post-115995585449390831</id><published>2006-10-04T02:53:00.000-07:00</published><updated>2006-10-04T03:08:48.563-07:00</updated><title type='text'>Yahoo Messenger virus/trojan/worm</title><content type='html'>Last day, a link appeared on an instant messenger window that seemed to be sent by one of my friend. I clicked on it. The link read, "A new virus has been found, click the link to know more and remove it".&lt;br /&gt;&lt;br /&gt;After clicking the link, another web page loaded and suddenly my firewall (Sygate Personal firewall, free edition, really recommendable) shown that an applicaiton (somename.exe) is trying to access a remote system. The application name was not familiar for me and I blocked its access. This was the starting of my two day mess.&lt;br /&gt;&lt;br /&gt;As soon as I blocked the access, my yahoo messenger's menu automatically activated and&lt;br /&gt;{it performed sending the link which I have got earlier to all in my messenger list.&lt;br /&gt;I found it as an malware activity and I suddenly typed and sent another message not to click on that link.&lt;br /&gt;I loggged off&lt;br /&gt;When I later logged-in, this activity again happened.&lt;br /&gt;&lt;br /&gt;I tried with Norton Anti-Virus, but no use.&lt;br /&gt;Then, I tried with ad-aware se personal, it found some errors.&lt;br /&gt;The most interesting tool I have found accidently was SpyWare removal tool at Netscape browser. It detected all the worm and removed it.&lt;br /&gt;&lt;br /&gt;I restarted the machine, and on taking the IE, the homepage was again found hijacked. I again run Ad-Aware SE and then, Netscapte spyware removal tool.&lt;br /&gt;&lt;br /&gt;The entried I got were, 1. svchost32.exe&lt;br /&gt;2. svhost.exe&lt;br /&gt;3.  manina~1.exe&lt;br /&gt;&lt;br /&gt;I searched the registry, and the system, and removed all entries found with this name.&lt;br /&gt;&lt;br /&gt;I have neither restarted my system nor logged in to Yahoo messenger. After that i will update this.&lt;br /&gt;&lt;br /&gt;I m sorry for writing this blog in a very short manner. But time constraint. I will soon update.&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Sajin Kokkad&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35484726-115995585449390831?l=sajinspeaks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sajinspeaks.blogspot.com/feeds/115995585449390831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35484726&amp;postID=115995585449390831' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35484726/posts/default/115995585449390831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35484726/posts/default/115995585449390831'/><link rel='alternate' type='text/html' href='http://sajinspeaks.blogspot.com/2006/10/yahoo-messenger-virustrojanworm.html' title='Yahoo Messenger virus/trojan/worm'/><author><name>Sajin Kokkad</name><uri>http://www.blogger.com/profile/08612657538924609656</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
