VideoAccessCodec

Posted by Marcin on May 9th, 2008

VideoAccessCodec has been updated. The codec installs the following files.

C:\Windows\vbksrofa.dll
C:\Windows\pvnsmfor.dll
C:\Windows\oadkxrts.exe
C:\Windows\mpfanvqg.dll

We have provided removal instructions for anybody unfortunate to have been infected by this codec.

Removal instructions for VideoAccessCodec

Trojan.Agent

Posted by Marcin on May 8th, 2008

Trojan.Agent is installed via an exploit. The trojan installs the following file:

C:\sysdump.dll

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Agent

Trojan.BHO

Posted by Marcin on May 8th, 2008

Trojan.BHO is installed via an exploit. The trojan installs the following file:

C:\autoex.dll

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.BHO

Spyware.Passwords

Posted by Marcin on May 8th, 2008

Spyware.Passwords installs via exploit without user interaction. Once installed, it slows down the system dramatically. The malware installs the following files:

C:\Program Files\DefWatch.exe
C:\Program Files\ctfmon.exe
C:\Windows\System32\donj32drv.dll

We have provided removal instructions for anybody unfortunate to have been infected by this malware.

Removal instructions for Spyware.Passwords

New Zlob

Posted by Marcin on May 7th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\rtmipr.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} = delayingly

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

New Zlob

Posted by Marcin on May 5th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\qdsba.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} = communa

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

New Zlob

Posted by Marcin on April 28th, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\uyhjw.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{4d51e91c-e917-4b7f-89ff-abe471e16927} = enswathes

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

New Zlob

Posted by Marcin on April 21st, 2008

New Zlob has been released again. It installs the following files and registry entries.

C:\Windows\System32\rkaxfza.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{eb9f614b-ea44-40d0-8829-542e4f254739} = garcea

We have provided removal instructions for anybody unfortunate to have been infected by this trojan.

Removal instructions for Trojan.Zlob

VideoAccessCodec

Posted by Marcin on April 19th, 2008

VideoAccessCodec has been updated. The codec installs the following files.

C:\Windows\dpevflbg.dll
C:\Windows\olgdqarf.exe
C:\Windows\vadokmxt.dll
C:\Windows\wdpoefan.dll
C:\Windows\wxvgsdbq.exe

We have provided removal instructions for anybody unfortunate to have been infected by this codec.

Removal instructions for VideoAccessCodec

New IEDefender Trojan

Posted by Marcin on April 15th, 2008

This trojan installs either IEDefender, Files Secure, or Malware Bell. The main file associated with the infection is below.

C:\Windows\netweb64c.dll

We have provided removal instructions for anybody unfortunate to have downloaded these applications.

Removal instructions for Malware Bell

Marcin Kleczynski


Wordpress Theme by Tech Replies
Powered By Wordpress
Copyright © 2008 Malwarebytes Blog. All rights reserved.