New Zlob

Posted by Marcin Kleczynski on April 28th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\uyhjw.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{4d51e91c-e917-4b7f-89ff-abe471e16927} = enswathes

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

IE AntiVirus

Posted by Marcin Kleczynski on April 24th, 2008

A new rogue by the name of IE AntiVirus has been discovered.

IE AntiVirus

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for IE AntiVirus

Marcin Kleczynski

New Zlob

Posted by Marcin Kleczynski on April 21st, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\rkaxfza.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{eb9f614b-ea44-40d0-8829-542e4f254739} = garcea

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

VideoAccessCodec

Posted by Marcin Kleczynski on April 19th, 2008

VideoAccessCodec has been updated. The codec installs the following files.

C:\Windows\dpevflbg.dll
C:\Windows\olgdqarf.exe
C:\Windows\vadokmxt.dll
C:\Windows\wdpoefan.dll
C:\Windows\wxvgsdbq.exe

We have provided removal instructions for anybody unfortunate to have been infected by this codec.

Removal instructions for VideoAccessCodec

New IEDefender Trojan

Posted by Marcin Kleczynski on April 15th, 2008

This trojan installs either IEDefender, Files Secure, or Malware Bell. The main file associated with the infection is below.

C:\Windows\netweb64c.dll

We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Malware Bell

Marcin Kleczynski

Malware Bell

Posted by Marcin Kleczynski on April 14th, 2008

A new rogue by the name of Malware Bell has been discovered. It is installed via the IE Defender trojan. In this specific case, the file most responsible for pushing the software is ps16sys.dll, which is located in the Windows directory..

Malware Bell

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Malware Bell

Marcin Kleczynski

VideoAccessCodec

Posted by Marcin Kleczynski on April 14th, 2008

VideoAccessCodec has been updated. The codec installs the following files.

C:\Windows\rtqmekwg.exe
C:\Windows\qtvglped.dll
C:\Windows\pmsoarbf.dll
C:\Windows\omlbpkaw.dll
C:\Windows\npqtsrak.exe

We have provided removal instructions for anybody unfortunate to have been infected by this codec.

Removal instructions for VideoAccessCodec

New Zlob

Posted by Marcin Kleczynski on April 14th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\vualf.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{12a31567-9883-4cc0-a684-ad5804394d69} = hemimorphite

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

C:\WINDOWS\winsurf.dll

Posted by Marcin Kleczynski on April 13th, 2008

A new Files Secure trojan is present. Below is the files and registry entries it creates. This trojan hijacks your search engine hits and recommends you purchase Files Secure. Removal instructions below.

C:\WINDOWS\winsurf.dll

HKLM\SOFTWARE\Classes\AppID\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}
HKLM\SOFTWARE\Classes\AppID\winsurf.dll
HKLM\SOFTWARE\Classes\winsurf.AVideo
HKLM\SOFTWARE\Classes\CLSID\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}
HKLM\SOFTWARE\Classes\Interface\{D263B532-C528-49E5-8BB6-80FA67332C9A}
HKLM\SOFTWARE\Classes\TypeLib\{7165223D-D2C9-422B-8126-411B11842B8B}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F91C786-BBA0-41D2-8B3D-B88242677BAC}

We have provided removal instructions for anybody unfortunate to have been infected by this trojan or Files Secure.

Removal instructions for Files Secure

VideoAccessCodec

Posted by Marcin Kleczynski on April 12th, 2008

VideoAccessCodec has been updated. The codec installs the following files.

C:\Windows\spnkfwad.exe
C:\Windows\sgoblxtm.dll
C:\Windows\ogxtsepr.dll
C:\Windows\dsktbwfe.dll

We have provided removal instructions for anybody unfortunate to have been infected by this codec.

Removal instructions for VideoAccessCodec


Wordpress Theme by Tech Replies
Powered By Wordpress
Copyright © 2008 Malwarebytes blog. All rights reserved.