New Zlob

Posted by Marcin on June 30th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\blbpeoy.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{ecc974ae-6ede-44a2-90da-93b996d8eaf8} = frizzed

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

Antivirus 2009

Posted by Marcin on June 29th, 2008

BleepingComputer recently blogged about Antivirus 2009 hijacking Google search results. BleepingComputer reported the advertising text as the following.

Google has detected unregistered Antivirus 2009 copy on your computer. Google recommends you to activate Antivirus 2009 to protect your PC from malicious intrusions from the Internet.

Antivirus 2009

Antivirus 2009 alert

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Antivirus 2009

Marcin Kleczynski

Doctor Antivirus 2008

Posted by Marcin on June 29th, 2008

Doctor Antivirus 2008

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Doctor Antivirus 2008

Marcin Kleczynski

Real AntiSpyware

Posted by Marcin on June 29th, 2008

Real AntiSpyware

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Real AntiSpyware

Marcin Kleczynski

WinAntispyware 2008

Posted by Marcin on June 29th, 2008

WinAntispyware 2008

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for WinAntispyware 2008

Marcin Kleczynski

SpywareScanner 2008

Posted by Marcin on June 29th, 2008

SpywareScanner 2008

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for SpywareScanner 2008

Marcin Kleczynski

PestSweeper

Posted by Marcin on June 29th, 2008

PestSweeper

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for PestSweeper

Marcin Kleczynski

New Zlob

Posted by Marcin on June 28th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\jhzpcn.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{2a7a8ce2-1eaf-4fc0-9158-958bb6bfa5c4} = dysmenorrhoea

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

New Zlob

Posted by Marcin on June 24th, 2008

New Zlob has been released again. It installs the following files, and registry entries.

C:\Windows\System32\ibmsmyi.dll
C:\Windows\System32\788877\788877.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{7BC9C2E2-73A6-4FCF-B73D-CBAA20B31C9B}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{049e2207-f9ef-40da-91f7-8819d0c33a84} = bergamiol

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

New Zlob

Posted by Marcin on June 20th, 2008

New Zlob has been released again. It installs the following files, and registry entries.

C:\Windows\System32\sgntu.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{c27abdde-8a43-4a7f-81c0-3fc3c952284f} = chicot

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob


Wordpress Theme by Tech Replies
Powered By Wordpress
Copyright © 2008 Malwarebytes Blog. All rights reserved.