<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Virus Found - Possible Threat &#8220;Trojan.Zlob&#8221; Undetected in many front line scanner</title>
	<atom:link href="http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/</link>
	<description>I would try to share what I have learnt</description>
	<pubDate>Fri, 21 Nov 2008 04:21:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: ValanBose - Elite Team Vss</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1718</link>
		<dc:creator>ValanBose - Elite Team Vss</dc:creator>
		<pubDate>Wed, 14 May 2008 19:50:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1718</guid>
		<description>* Issue :-
Getting lot of porn websites poping up.
Getting lot of spyware popups.
Does your computer infected with Trojan.Vundo.

* Steps to Fix :-
* Start your comp in safe mode with networking.
* Go to the following location and look the following files if find those files Delete it..

C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\DNnVyyay.ini
C:\WINDOWS\SYSTEM32\DNnVyyay.ini2
C:\WINDOWS\system32\lTCfPqru.ini
C:\WINDOWS\SYSTEM32\lTCfPqru.ini2
C:\Documents and Settings\Alan Borson\Application Data\CURITY~1
C:\Documents and Settings\Alan Borson\Application Data\SMBOLS~1
C:\Documents and Settings\Alan Borson\Application Data\SSTEM~1
C:\Documents and Settings\Alan Borson\Application Data\WinIFixer.com
C:\Documents and Settings\Alan Borson\Application Data\WinTouch
C:\Documents and Settings\Alan Borson\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Alan Borson\My Documents\CROSOF~1.NET
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1\?ppPatch\
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1\ati2evxx.exe
C:\Documents and Settings\Alan Borson\My Documents\STEM~1
C:\Documents and Settings\Alan Borson\My Documents\WNSXS~1
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\mbols~1
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Temporary
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\webhdll.dll
C:\Program Files\webhancer\Programs\whinstaller.exe
C:\WINDOWS\123messenger.per
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\apphelp32.dll
C:\WINDOWS\asferror32.dll
C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\athprxy32.dll
C:\WINDOWS\ati2dvaa32.dll
C:\WINDOWS\ati2dvag32.dll
C:\WINDOWS\audiosrv32.dll
C:\WINDOWS\autodisc32.dll
C:\WINDOWS\avifile32.dll
C:\WINDOWS\avisynthex32.dll
C:\WINDOWS\aviwrap32.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\browserad.dll
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\changeurl_30.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\didduid.ini
C:\WINDOWS\licencia.txt
C:\WINDOWS\megavid.cdt
C:\WINDOWS\msa64chk.dll
C:\WINDOWS\msapasrc.dll
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\ntnut.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\saiemod.dll
C:\WINDOWS\secure32.html
C:\WINDOWS\shdocpe.dll
C:\WINDOWS\shdocpl.dll
C:\WINDOWS\start.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\SYSTEM32\bedcajcc.ini
C:\WINDOWS\system32\ccjacdeb.dll
C:\WINDOWS\SYSTEM32\DNnVyyay.ini
C:\WINDOWS\SYSTEM32\DNnVyyay.ini2
C:\WINDOWS\system32\fdwpscux.ini
C:\WINDOWS\system32\iqhhytgm.ini
C:\WINDOWS\SYSTEM32\lTCfPqru.ini
C:\WINDOWS\SYSTEM32\lTCfPqru.ini2
C:\WINDOWS\system32\mgtyhhqi.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\tvyknjtf.ini
C:\WINDOWS\system32\xucspwdf.dll
C:\WINDOWS\telefonos.txt
C:\WINDOWS\textos.txt
C:\WINDOWS\voiceip.dll
C:\WINDOWS\Web\default.htt
C:\WINDOWS\winsb.dll
"C:\WINDOWS\system32\yaywuuVn.dll"
C:\WINDOWS\system32\urqPfCTl.dll
C:\WINDOWS\system32\yaywuuVn.dll
C:\WINDOWS\system32\whameprt.dll
* yaywuuVn.dll -- This file could be winlogon entry.
* So start &#62; run&#62; type regedit
* Take a backup of registry.
*HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify -- check for that file or folder if you find so delete it.
* Search the file under registry also and delete it.
* Now you can look for 
c:\program files\.....(any unwanted programs delete it).
* Now you can delete all Temp files and prefetch.
* Empty the recycle bin.
* Restart the computer in normal mode.
* Now try to access the IE check whether you find any poups.
* I hope you wont get any poups..if so let me Know..
i will guide to run some removal tool to fix it..

ValanBose
Vss Elite.</description>
		<content:encoded><![CDATA[<p>* Issue :-<br />
Getting lot of porn websites poping up.<br />
Getting lot of spyware popups.<br />
Does your computer infected with Trojan.Vundo.</p>
<p>* Steps to Fix :-<br />
* Start your comp in safe mode with networking.<br />
* Go to the following location and look the following files if find those files Delete it..</p>
<p>C:\WINDOWS\pskt.ini<br />
C:\WINDOWS\SYSTEM32\DNnVyyay.ini<br />
C:\WINDOWS\SYSTEM32\DNnVyyay.ini2<br />
C:\WINDOWS\system32\lTCfPqru.ini<br />
C:\WINDOWS\SYSTEM32\lTCfPqru.ini2<br />
C:\Documents and Settings\Alan Borson\Application Data\CURITY~1<br />
C:\Documents and Settings\Alan Borson\Application Data\SMBOLS~1<br />
C:\Documents and Settings\Alan Borson\Application Data\SSTEM~1<br />
C:\Documents and Settings\Alan Borson\Application Data\WinIFixer.com<br />
C:\Documents and Settings\Alan Borson\Application Data\WinTouch<br />
C:\Documents and Settings\Alan Borson\Application Data\WinTouch\wintouch.cfg<br />
C:\Documents and Settings\Alan Borson\My Documents\CROSOF~1.NET<br />
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1<br />
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1\?ppPatch\<br />
C:\Documents and Settings\Alan Borson\My Documents\PPPATC~1\ati2evxx.exe<br />
C:\Documents and Settings\Alan Borson\My Documents\STEM~1<br />
C:\Documents and Settings\Alan Borson\My Documents\WNSXS~1<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat<br />
C:\Documents and Settings\All Users\Application Data\Rabio<br />
C:\Program Files\JavaCore<br />
C:\Program Files\JavaCore\JavaCore.exe<br />
C:\Program Files\mbols~1<br />
C:\Program Files\outerinfo<br />
C:\Program Files\outerinfo\FF\chrome.manifest<br />
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt<br />
C:\Program Files\outerinfo\FF\install.rdf<br />
C:\Program Files\outerinfo\Terms.rtf<br />
C:\Program Files\Temporary<br />
C:\Program Files\webhancer<br />
C:\Program Files\webhancer\Programs\webhdll.dll<br />
C:\Program Files\webhancer\Programs\whinstaller.exe<br />
C:\WINDOWS\123messenger.per<br />
C:\WINDOWS\2020search.dll<br />
C:\WINDOWS\2020search2.dll<br />
C:\WINDOWS\apphelp32.dll<br />
C:\WINDOWS\asferror32.dll<br />
C:\WINDOWS\asycfilt32.dll<br />
C:\WINDOWS\athprxy32.dll<br />
C:\WINDOWS\ati2dvaa32.dll<br />
C:\WINDOWS\ati2dvag32.dll<br />
C:\WINDOWS\audiosrv32.dll<br />
C:\WINDOWS\autodisc32.dll<br />
C:\WINDOWS\avifile32.dll<br />
C:\WINDOWS\avisynthex32.dll<br />
C:\WINDOWS\aviwrap32.dll<br />
C:\WINDOWS\bjam.dll<br />
C:\WINDOWS\bokja.exe<br />
C:\WINDOWS\browserad.dll<br />
C:\WINDOWS\cdsm32.dll<br />
C:\WINDOWS\changeurl_30.dll<br />
C:\WINDOWS\cookies.ini<br />
C:\WINDOWS\default.htm<br />
C:\WINDOWS\didduid.ini<br />
C:\WINDOWS\licencia.txt<br />
C:\WINDOWS\megavid.cdt<br />
C:\WINDOWS\msa64chk.dll<br />
C:\WINDOWS\msapasrc.dll<br />
C:\WINDOWS\mspphe.dll<br />
C:\WINDOWS\mssvr.exe<br />
C:\WINDOWS\ntnut.exe<br />
C:\WINDOWS\pskt.ini<br />
C:\WINDOWS\saiemod.dll<br />
C:\WINDOWS\secure32.html<br />
C:\WINDOWS\shdocpe.dll<br />
C:\WINDOWS\shdocpl.dll<br />
C:\WINDOWS\start.exe<br />
C:\WINDOWS\stcloader.exe<br />
C:\WINDOWS\swin32.dll<br />
C:\WINDOWS\SYSTEM32\bedcajcc.ini<br />
C:\WINDOWS\system32\ccjacdeb.dll<br />
C:\WINDOWS\SYSTEM32\DNnVyyay.ini<br />
C:\WINDOWS\SYSTEM32\DNnVyyay.ini2<br />
C:\WINDOWS\system32\fdwpscux.ini<br />
C:\WINDOWS\system32\iqhhytgm.ini<br />
C:\WINDOWS\SYSTEM32\lTCfPqru.ini<br />
C:\WINDOWS\SYSTEM32\lTCfPqru.ini2<br />
C:\WINDOWS\system32\mgtyhhqi.dll<br />
C:\WINDOWS\system32\pac.txt<br />
C:\WINDOWS\system32\tvyknjtf.ini<br />
C:\WINDOWS\system32\xucspwdf.dll<br />
C:\WINDOWS\telefonos.txt<br />
C:\WINDOWS\textos.txt<br />
C:\WINDOWS\voiceip.dll<br />
C:\WINDOWS\Web\default.htt<br />
C:\WINDOWS\winsb.dll<br />
&#8220;C:\WINDOWS\system32\yaywuuVn.dll&#8221;<br />
C:\WINDOWS\system32\urqPfCTl.dll<br />
C:\WINDOWS\system32\yaywuuVn.dll<br />
C:\WINDOWS\system32\whameprt.dll<br />
* yaywuuVn.dll &#8212; This file could be winlogon entry.<br />
* So start &gt; run&gt; type regedit<br />
* Take a backup of registry.<br />
*HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify &#8212; check for that file or folder if you find so delete it.<br />
* Search the file under registry also and delete it.<br />
* Now you can look for<br />
c:\program files\&#8230;..(any unwanted programs delete it).<br />
* Now you can delete all Temp files and prefetch.<br />
* Empty the recycle bin.<br />
* Restart the computer in normal mode.<br />
* Now try to access the IE check whether you find any poups.<br />
* I hope you wont get any poups..if so let me Know..<br />
i will guide to run some removal tool to fix it..</p>
<p>ValanBose<br />
Vss Elite.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: layal</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1552</link>
		<dc:creator>layal</dc:creator>
		<pubDate>Thu, 24 Apr 2008 14:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1552</guid>
		<description>hi</description>
		<content:encoded><![CDATA[<p>hi</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ValanBose - Elite Team Vss</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1472</link>
		<dc:creator>ValanBose - Elite Team Vss</dc:creator>
		<pubDate>Tue, 15 Apr 2008 16:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1472</guid>
		<description>Trojan Zlob\Trojan.Downloader :-
===============================
It may come in an email asking you to check out a movie file or it may seek to push its way to your computer from malicious websites. In both cases a 'codec' will be offered in the guise of helping you watch a streaming video, but instead of showing the movie it will install a stealthy Trojan Downloader in your computer. That is Zlob Trojan.</description>
		<content:encoded><![CDATA[<p>Trojan Zlob\Trojan.Downloader :-<br />
===============================<br />
It may come in an email asking you to check out a movie file or it may seek to push its way to your computer from malicious websites. In both cases a &#8216;codec&#8217; will be offered in the guise of helping you watch a streaming video, but instead of showing the movie it will install a stealthy Trojan Downloader in your computer. That is Zlob Trojan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ValanBose</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1471</link>
		<dc:creator>ValanBose</dc:creator>
		<pubDate>Tue, 15 Apr 2008 16:39:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-1471</guid>
		<description>Trojan.Dropper - Its a virus,that could creat a base file under system32 location,whenever computer restarts the file will change and it drop the file in the same location.</description>
		<content:encoded><![CDATA[<p>Trojan.Dropper - Its a virus,that could creat a base file under system32 location,whenever computer restarts the file will change and it drop the file in the same location.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nikolaj</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-500</link>
		<dc:creator>nikolaj</dc:creator>
		<pubDate>Sun, 23 Dec 2007 15:43:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-500</guid>
		<description>thnx for the news</description>
		<content:encoded><![CDATA[<p>thnx for the news</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Piyush</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-218</link>
		<dc:creator>Piyush</dc:creator>
		<pubDate>Wed, 31 Oct 2007 09:50:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-218</guid>
		<description>HO come u scan with alll the AV simltenously :O</description>
		<content:encoded><![CDATA[<p>HO come u scan with alll the AV simltenously :O</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Piyush</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-217</link>
		<dc:creator>Piyush</dc:creator>
		<pubDate>Wed, 31 Oct 2007 09:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-217</guid>
		<description>Great................

Big guns are like....</description>
		<content:encoded><![CDATA[<p>Great&#8230;&#8230;&#8230;&#8230;&#8230;.</p>
<p>Big guns are like&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Utsav</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-210</link>
		<dc:creator>Utsav</dc:creator>
		<pubDate>Mon, 29 Oct 2007 15:44:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-210</guid>
		<description>lollzzzz.</description>
		<content:encoded><![CDATA[<p>lollzzzz.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ravi</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-209</link>
		<dc:creator>ravi</dc:creator>
		<pubDate>Mon, 29 Oct 2007 14:04:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-209</guid>
		<description>Top paid AV fails.........
surprised!!!!</description>
		<content:encoded><![CDATA[<p>Top paid AV fails&#8230;&#8230;&#8230;<br />
surprised!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anandk</title>
		<link>http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-208</link>
		<dc:creator>anandk</dc:creator>
		<pubDate>Mon, 29 Oct 2007 12:33:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.chotocheeta.com/2007/10/29/virus-found-possible-threat-trojanzlob-undetected-in-many-front-line-scanner/#comment-208</guid>
		<description>really surprising to see 'big guns' failing...</description>
		<content:encoded><![CDATA[<p>really surprising to see &#8216;big guns&#8217; failing&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
