<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Malwarebytes Blog</title>
	<link>http://malwarebytes.besttechie.net</link>
	<description></description>
	<pubDate>Fri, 09 May 2008 21:19:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>VideoAccessCodec</title>
		<link>http://malwarebytes.besttechie.net/2008/05/09/videoaccesscodec-4/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/09/videoaccesscodec-4/#comments</comments>
		<pubDate>Fri, 09 May 2008 21:19:44 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[codec]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[mpfanvqg.dll]]></category>

		<category><![CDATA[oadkxrts.exe]]></category>

		<category><![CDATA[pvnsmfor.dll]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[vbksrofa.dll]]></category>

		<category><![CDATA[VideoAccessCodec]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/09/videoaccesscodec-4/</guid>
		<description><![CDATA[VideoAccessCodec has been updated. The codec installs the following files.
C:\Windows\vbksrofa.dll
C:\Windows\pvnsmfor.dll
C:\Windows\oadkxrts.exe
C:\Windows\mpfanvqg.dll
We have provided removal instructions for anybody unfortunate to have been infected by this codec.
Removal instructions for VideoAccessCodec
]]></description>
			<content:encoded><![CDATA[<p>VideoAccessCodec has been updated. The codec installs the following files.</p>
<p>C:\Windows\<strong>vbksrofa.dll</strong><br />
C:\Windows\<strong>pvnsmfor.dll</strong><br />
C:\Windows\<strong>oadkxrts.exe</strong><br />
C:\Windows\<strong>mpfanvqg.dll</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this codec.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4064" title="Removal instructions for VideoAccessCodec"><strong>Removal instructions for VideoAccessCodec</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/09/videoaccesscodec-4/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trojan.Agent</title>
		<link>http://malwarebytes.besttechie.net/2008/05/08/trojanagent/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/08/trojanagent/#comments</comments>
		<pubDate>Thu, 08 May 2008 22:21:56 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[autoex.dll]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[trojan.agent]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/08/trojanagent/</guid>
		<description><![CDATA[Trojan.Agent is installed via an exploit. The trojan installs the following file:
C:\sysdump.dll
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Agent
]]></description>
			<content:encoded><![CDATA[<p>Trojan.Agent is installed via an exploit. The trojan installs the following file:</p>
<p><strong>C:\sysdump.dll</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4558" title="Removal instructions for Trojan.Agent"><strong>Removal instructions for Trojan.Agent</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/08/trojanagent/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trojan.BHO</title>
		<link>http://malwarebytes.besttechie.net/2008/05/08/trojanbho/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/08/trojanbho/#comments</comments>
		<pubDate>Thu, 08 May 2008 22:16:56 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[autoex.dll]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[trojan.bho]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/08/trojanbho/</guid>
		<description><![CDATA[Trojan.BHO is installed via an exploit. The trojan installs the following file:
C:\autoex.dll
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.BHO
]]></description>
			<content:encoded><![CDATA[<p>Trojan.BHO is installed via an exploit. The trojan installs the following file:</p>
<p><strong>C:\autoex.dll</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4557" title="Removal instructions for Trojan.BHO"><strong>Removal instructions for Trojan.BHO</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/08/trojanbho/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spyware.Passwords</title>
		<link>http://malwarebytes.besttechie.net/2008/05/08/spywarepasswords/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/08/spywarepasswords/#comments</comments>
		<pubDate>Thu, 08 May 2008 22:07:32 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[spyware.passwords]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/08/spywarepasswords/</guid>
		<description><![CDATA[Spyware.Passwords installs via exploit without user interaction. Once installed, it slows down the system dramatically. The malware installs the following files:
C:\Program Files\DefWatch.exe
C:\Program Files\ctfmon.exe
C:\Windows\System32\donj32drv.dll
We have provided removal instructions for anybody unfortunate to have been infected by this malware.
Removal instructions for Spyware.Passwords
]]></description>
			<content:encoded><![CDATA[<p>Spyware.Passwords installs via exploit without user interaction. Once installed, it slows down the system dramatically. The malware installs the following files:</p>
<p>C:\Program Files\<strong>DefWatch.exe</strong><br />
C:\Program Files\<strong>ctfmon.exe</strong><br />
C:\Windows\System32\<strong>donj32drv.dll</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this malware.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4556" title="Removal instructions for Spyware.Passwords"><strong>Removal instructions for Spyware.Passwords</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/08/spywarepasswords/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Zlob</title>
		<link>http://malwarebytes.besttechie.net/2008/05/07/new-zlob-12/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/07/new-zlob-12/#comments</comments>
		<pubDate>Wed, 07 May 2008 21:28:46 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[rtmipr.dll]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[zlob]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/07/new-zlob-12/</guid>
		<description><![CDATA[New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\rtmipr.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} = delayingly
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
]]></description>
			<content:encoded><![CDATA[<p>New Zlob has been released again. It installs the following files and registry entries.</p>
<p>C:\Windows\System32\<strong>rtmipr.dll</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler<br />
<strong>{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} = delayingly</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4052" title="Removal instructions for Trojan.Zlob"><strong>Removal instructions for Trojan.Zlob</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/07/new-zlob-12/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Zlob</title>
		<link>http://malwarebytes.besttechie.net/2008/05/05/new-zlob-11/</link>
		<comments>http://malwarebytes.besttechie.net/2008/05/05/new-zlob-11/#comments</comments>
		<pubDate>Tue, 06 May 2008 03:17:00 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[qdsba.dll]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[zlob]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/05/05/new-zlob-11/</guid>
		<description><![CDATA[New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\qdsba.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} = communa
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
]]></description>
			<content:encoded><![CDATA[<p>New Zlob has been released again. It installs the following files and registry entries.</p>
<p>C:\Windows\System32\<strong>qdsba.dll</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler<br />
<strong>{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} = communa</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4052" title="Removal instructions for Trojan.Zlob"><strong>Removal instructions for Trojan.Zlob</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/05/05/new-zlob-11/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Zlob</title>
		<link>http://malwarebytes.besttechie.net/2008/04/28/new-zlob-10/</link>
		<comments>http://malwarebytes.besttechie.net/2008/04/28/new-zlob-10/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 22:11:20 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[uyhjw.dll]]></category>

		<category><![CDATA[zlob]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/04/28/new-zlob-10/</guid>
		<description><![CDATA[New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\uyhjw.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{4d51e91c-e917-4b7f-89ff-abe471e16927} = enswathes
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
]]></description>
			<content:encoded><![CDATA[<p>New Zlob has been released again. It installs the following files and registry entries.</p>
<p>C:\Windows\System32\<strong>uyhjw.dll</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler<br />
<strong>{4d51e91c-e917-4b7f-89ff-abe471e16927} = enswathes</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4052" title="Removal instructions for Trojan.Zlob"><strong>Removal instructions for Trojan.Zlob</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/04/28/new-zlob-10/feed/</wfw:commentRss>
		</item>
		<item>
		<title>IE AntiVirus</title>
		<link>http://malwarebytes.besttechie.net/2008/04/24/ie-antivirus/</link>
		<comments>http://malwarebytes.besttechie.net/2008/04/24/ie-antivirus/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 01:18:11 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Rogues]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[IE AntiVirus]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/04/24/ie-antivirus/</guid>
		<description><![CDATA[A new rogue by the name of IE AntiVirus has been discovered.

If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.
Removal instructions for IE AntiVirus
Marcin Kleczynski
]]></description>
			<content:encoded><![CDATA[<p>A new rogue by the name of IE AntiVirus has been discovered.</p>
<p><img border="0" width="400" src="http://www.malwarebytes.org/images/forumhelp/ieantivirus.png" alt="IE AntiVirus" height="310" /></p>
<p>If you have seen any of the windows above on your computer, it is recommended that you follow these instructions. We have provided removal instructions for anybody unfortunate to have downloaded these applications.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4420" title="Removal instructions for IE AntiVirus"><strong>Removal instructions for IE AntiVirus</strong></a></p>
<p>Marcin Kleczynski</p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/04/24/ie-antivirus/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Zlob</title>
		<link>http://malwarebytes.besttechie.net/2008/04/21/new-zlob-9/</link>
		<comments>http://malwarebytes.besttechie.net/2008/04/21/new-zlob-9/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 19:49:58 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rkaxfza.dll]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[zlob]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/04/21/new-zlob-9/</guid>
		<description><![CDATA[New Zlob has been released again. It installs the following files and registry entries.
C:\Windows\System32\rkaxfza.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{eb9f614b-ea44-40d0-8829-542e4f254739} = garcea
We have provided removal instructions for anybody unfortunate to have been infected by this trojan.
Removal instructions for Trojan.Zlob
]]></description>
			<content:encoded><![CDATA[<p>New Zlob has been released again. It installs the following files and registry entries.</p>
<p>C:\Windows\System32\<strong>rkaxfza.dll</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler<br />
<strong>{eb9f614b-ea44-40d0-8829-542e4f254739} = garcea</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this trojan.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4052" title="Removal instructions for Trojan.Zlob"><strong>Removal instructions for Trojan.Zlob</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/04/21/new-zlob-9/feed/</wfw:commentRss>
		</item>
		<item>
		<title>VideoAccessCodec</title>
		<link>http://malwarebytes.besttechie.net/2008/04/19/videoaccesscodec-3/</link>
		<comments>http://malwarebytes.besttechie.net/2008/04/19/videoaccesscodec-3/#comments</comments>
		<pubDate>Sat, 19 Apr 2008 15:42:08 +0000</pubDate>
		<dc:creator>Marcin</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[anti-spyware]]></category>

		<category><![CDATA[codec]]></category>

		<category><![CDATA[dpevflbg.dll]]></category>

		<category><![CDATA[instructions]]></category>

		<category><![CDATA[Malwarebytes]]></category>

		<category><![CDATA[olgdqarf.exe]]></category>

		<category><![CDATA[removal]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[vadokmxt.dll]]></category>

		<category><![CDATA[VideoAccessCodec]]></category>

		<category><![CDATA[wdpoefan.dll]]></category>

		<category><![CDATA[wxvgsdbq.exe]]></category>

		<guid isPermaLink="false">http://malwarebytes.besttechie.net/2008/04/19/videoaccesscodec-3/</guid>
		<description><![CDATA[VideoAccessCodec has been updated. The codec installs the following files.
C:\Windows\dpevflbg.dll
C:\Windows\olgdqarf.exe
C:\Windows\vadokmxt.dll
C:\Windows\wdpoefan.dll
C:\Windows\wxvgsdbq.exe
We have provided removal instructions for anybody unfortunate to have been infected by this codec.
Removal instructions for VideoAccessCodec
]]></description>
			<content:encoded><![CDATA[<p>VideoAccessCodec has been updated. The codec installs the following files.</p>
<p>C:\Windows\<strong>dpevflbg.dll</strong><br />
C:\Windows\<strong>olgdqarf.exe</strong><br />
C:\Windows\<strong>vadokmxt.dll</strong><br />
C:\Windows\<strong>wdpoefan.dll</strong><br />
C:\Windows\<strong>wxvgsdbq.exe</strong></p>
<p>We have provided removal instructions for anybody unfortunate to have been infected by this codec.</p>
<p><a target="_blank" href="http://www.malwarebytes.org/forums/index.php?showtopic=4064" title="Removal instructions for VideoAccessCodec"><strong>Removal instructions for VideoAccessCodec</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarebytes.besttechie.net/2008/04/19/videoaccesscodec-3/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
