Showing posts with label Zlob. Show all posts
Showing posts with label Zlob. Show all posts

Friday, January 9, 2009

Zlob

A message found in a Zlob binary:

For Windows Defender's Team:
I saw your post in the blog (10-Oct-2008) about my previous message.
Just want to say 'Hello' from Russia.
You are really good guys.
It was a surprise for me that Microsoft can respond on threats so fast.
I can't sign here now (he-he, sorry), how it was some years ago for more seriously vulnerability for all Windows ;)
Happy New Year, guys, and good luck!

P.S. BTW, we are closing soon. Not because of your work. :-))
So, you will not see some of my great ;) ideas in that family of software.
Try to search in exploits/shellcodes and rootkits.
Also, it is funny (probably for you), but Microsoft offered me a job to help
improve some of Vista's protection. It's not interesting for me, just a life's irony.

This is a response to Microsoft Windows Defender's Team, which found a first message in a previous binary and post a topic on their blog.
Post in French on MAD's Blog

Sunday, December 21, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\ijofmsu.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2ecca339-c274-40e3-a582-ef4c0e917639}"="bussebuschke"

It also installs Toolbar, BHO, Antivirus Trigger software...

SmitfraudFix removes the infection.

Wednesday, December 10, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\pgfshvp.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{50e9d039-fb50-4020-a841-1d226ae52b22}"="defroster"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Monday, December 8, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\elmnplw.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{341bd909-3367-4307-b37d-fb1cc56387ad}"="cacara"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Wednesday, December 3, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\gtckad.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{61d70260-527c-44e8-bb23-2243e93808d3}"="achromatic"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Tuesday, December 2, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\pbhha.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{51e7273d-911a-445a-bf46-bd4b86b0e87b}"="fddi"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.

Sunday, November 30, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\cwegus.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{4d5b7736-a3bc-4e5b-9fa2-1bcc3e587abb}"="evacuative"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.

Friday, November 28, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\ftfea.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{22ef8ba1-a18c-4ad3-ad84-01b95b581c5c}"="fractabling"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.

Monday, November 24, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\eebpj.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{854b8525-c907-4258-bc2e-7b118037419c}"="disaffiliation"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.

Thursday, November 20, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\tiltmeo.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e0feeb92-908e-46d2-8a66-88c5295f2629}"="crimsonness"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.

Sunday, November 16, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\gowqug.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1f3dd9bf-1472-4a8b-b295-b596a597149b}"="behaves"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.

Thursday, November 13, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\wakjs.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{257f6f44-2c64-46bb-acb4-55f9b9e0ae08}"="flaxen"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.

Friday, November 7, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\ebmkdz.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{6b9a461b-893f-45ee-8c59-06d3a2223b24}"="cypselomorphae"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Tuesday, November 4, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\qfrmwmq.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d54f12f7-4d76-4c39-a096-e51ef5d33f2b}"="displume"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Friday, October 31, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\duzakwq.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7ca07c92-0ab2-4346-b119-a076695d46ed}"="hemielytron"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Thursday, October 30, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\vimhx.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d04bbe06-7ce7-405e-8730-cd56d9531cbb}"="bismuthiferous"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Sunday, October 26, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\gcqltg.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ba934431-76af-4c99-93c2-c3d21944a72e}"="gey"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Thursday, October 23, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\bcxjqr.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e3623691-f85d-48d8-8e4d-abe79077f841}"="awash"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Saturday, October 18, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\teoga.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2f199d0e-f3e7-41a7-a060-816c24cceea0}"="emaa"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.

Monday, October 13, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\eivrbsi.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{da75fab1-136e-4ead-834d-0e04fbd6edc1}"="euphuize"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.