Posted by Marcin on April 28th, 2008
New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\uyhjw.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{4d51e91c-e917-4b7f-89ff-abe471e16927} = enswathes
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
Posted by Marcin on April 24th, 2008
A new rogue by the name of IE AntiVirus has been discovered.

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.
Removal instructions for IE AntiVirus
Marcin Kleczynski
Posted by Marcin on April 21st, 2008
New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\rkaxfza.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{eb9f614b-ea44-40d0-8829-542e4f254739} = garcea
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
Posted by Marcin on April 19th, 2008
VideoAccessCodec has been updated. The codec installs the following files.
C:\Windows\dpevflbg.dll
C:\Windows\olgdqarf.exe
C:\Windows\vadokmxt.dll
C:\Windows\wdpoefan.dll
C:\Windows\wxvgsdbq.exe
We have provided removal instructions for anybody unfortunate to have been infected by this codec.
Removal instructions for VideoAccessCodec
Posted by Marcin on April 15th, 2008
This trojan installs either IEDefender, Files Secure, or Malware Bell. The main file associated with the infection is below.
C:\Windows\netweb64c.dll
We have provided removal instructions for anybody unfortunate to have downloaded these applications.
Removal instructions for Malware Bell
Marcin Kleczynski
Posted by Marcin on April 14th, 2008
A new rogue by the name of Malware Bell has been discovered. It is installed via the IE Defender trojan. In this specific case, the file most responsible for pushing the software is ps16sys.dll, which is located in the Windows directory..

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.
Removal instructions for Malware Bell
Marcin Kleczynski
Posted by Marcin on April 14th, 2008
VideoAccessCodec has been updated. The codec installs the following files.
C:\Windows\rtqmekwg.exe
C:\Windows\qtvglped.dll
C:\Windows\pmsoarbf.dll
C:\Windows\omlbpkaw.dll
C:\Windows\npqtsrak.exe
We have provided removal instructions for anybody unfortunate to have been infected by this codec.
Removal instructions for VideoAccessCodec
Posted by Marcin on April 14th, 2008
New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\vualf.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{12a31567-9883-4cc0-a684-ad5804394d69} = hemimorphite
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
Posted by Marcin on April 13th, 2008
A new Files Secure trojan is present. Below is the files and registry entries it creates. This trojan hijacks your search engine hits and recommends you purchase Files Secure. Removal instructions below.
C:\WINDOWS\winsurf.dll
HKLM\SOFTWARE\Classes\AppID\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}
HKLM\SOFTWARE\Classes\AppID\winsurf.dll
HKLM\SOFTWARE\Classes\winsurf.AVideo
HKLM\SOFTWARE\Classes\CLSID\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}
HKLM\SOFTWARE\Classes\Interface\{D263B532-C528-49E5-8BB6-80FA67332C9A}
HKLM\SOFTWARE\Classes\TypeLib\{7165223D-D2C9-422B-8126-411B11842B8B}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}
We have provided removal instructions for anybody unfortunate to have been infected by this trojan or Files Secure.
Removal instructions for Files Secure
Posted by Marcin on April 12th, 2008
VideoAccessCodec has been updated. The codec installs the following files.
C:\Windows\spnkfwad.exe
C:\Windows\sgoblxtm.dll
C:\Windows\ogxtsepr.dll
C:\Windows\dsktbwfe.dll
We have provided removal instructions for anybody unfortunate to have been infected by this codec.
Removal instructions for VideoAccessCodec
Recent Comments