VideoAccessCodec has been update, it installs the following files:
%WINDOWS%\boqnrwdm???.dll (where ? is a random caracter)
%WINDOWS%\atfxqogp.dll
%WINDOWS%\vltdfabw.dll
%WINDOWS%\vregfwlx.dll
%WINDOWS%\xmpstean.exe
%WINDOWS%\eqln.exe
Use SmitfraudFix to remove the infection.
Thursday, May 29, 2008
Tuesday, May 27, 2008
VideoAccessCodec (VAC), Virus Alert!
The new version of Video Access Codec infection installs some policies that prevent Command Line execution.
It also displays a message: Virus Alert! in the Windows Clock, removes some Start Menu icons, and hides drives icons.
Use SmitfraudFix to remove the infection.
It also displays a message: Virus Alert! in the Windows Clock, removes some Start Menu icons, and hides drives icons.
Use SmitfraudFix to remove the infection.
Libellés :
DesktopHijack,
Malware,
ScreenShots,
VAC
Friday, May 23, 2008
Video ActiveX Object Error
Fake Video suggesting Fake Codec installation, and dropping iSecurity Malware (infected Windows Security icon in Control Panel).
Thanks to nosirrah.
Thanks to nosirrah.
Libellés :
FakeSiteMessage,
ISecurity,
Malware,
ScreenShots
Sunday, May 18, 2008
IE Defender, Files Secure, Malware Bell, IE Antivirus
IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: ap, od, ik, sa, do, unbe, gy, ps, xu
Files could look like: iksaps.dll, apunbeps.dll, apsagy.dll ...
and displays alert messages:
Use SmitfraudFix to remove the infection.
Files could look like: iksaps.dll, apunbeps.dll, apsagy.dll ...
and displays alert messages:
Use SmitfraudFix to remove the infection.
Friday, May 16, 2008
Zlob, VideoAccessCodec (VAC)
Websites proposing malware installation under fake codec message have seen an evolution, according to Secure Computing, Zlob threat hides as free, faked MP3 download.
VideoAccessCodec fake messages content have also changed, proposing a Fake Flash installation:
Thanks to MAD.
VideoAccessCodec fake messages content have also changed, proposing a Fake Flash installation:
Thanks to MAD.
Libellés :
FakeSiteMessage,
Malware,
ScreenShots,
VAC
Thursday, May 15, 2008
VideoAccessCodec (VAC)
VideoAccessCodec has been update, it installs the following files:
%WINDOWS%\fvowketq???.dll (where ? is a random caracter)
%WINDOWS%\pvnsmfor.dll
%WINDOWS%\mpfanvqg.dll
%WINDOWS%\vbksrofa.dll
%WINDOWS%\oadkxrts.exe
%WINDOWS%\epfg.exe
Use SmitfraudFix to remove the infection.
%WINDOWS%\fvowketq???.dll (where ? is a random caracter)
%WINDOWS%\pvnsmfor.dll
%WINDOWS%\mpfanvqg.dll
%WINDOWS%\vbksrofa.dll
%WINDOWS%\oadkxrts.exe
%WINDOWS%\epfg.exe
Use SmitfraudFix to remove the infection.
Wednesday, May 14, 2008
IE Defender, Files Secure, Malware Bell, IE Antivirus
IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs the following a file:
%WINDOWS%\iebho.dll
and displays alert messages:
Use SmitfraudFix to remove the infection.
%WINDOWS%\iebho.dll
and displays alert messages:
Use SmitfraudFix to remove the infection.
Wednesday, May 7, 2008
Zlob
Zlob fake codec has been update. It drops the following file:
%SYSTEM%\rtmipr.dll
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193}"="delayingly"
It also installs Toolbar, BHO, VirusHeat Rogue software...
SmitfraudFix removes the infection.
%SYSTEM%\rtmipr.dll
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193}"="delayingly"
It also installs Toolbar, BHO, VirusHeat Rogue software...
SmitfraudFix removes the infection.
Tuesday, May 6, 2008
Zlob
Zlob fake codec has been update. It drops the following file:
%SYSTEM%\qdsba.dll
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{af73a174-ea1b-4f0b-b0b1-fe1486a6719c}"="communa"
It also installs Toolbar, BHO, VirusHeat Rogue software...
SmitfraudFix removes the infection.
%SYSTEM%\qdsba.dll
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{af73a174-ea1b-4f0b-b0b1-fe1486a6719c}"="communa"
It also installs Toolbar, BHO, VirusHeat Rogue software...
SmitfraudFix removes the infection.
VirusHeat 4.4
A new version of the rogue VirusHeat has been released. This rogues looks like: VirusProtect, VirusRay, Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.
Libellés :
Rogues,
ScreenShots
Sunday, May 4, 2008
IE Defender, Files Secure, Malware Bell, IE Antivirus
IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: f, vid, pn, as, op, k, 32, 16, 64
Files could look like: vidk32.dll...
and displays alert messages:
Use SmitfraudFix to remove the infection.
Files could look like: vidk32.dll...
and displays alert messages:
Use SmitfraudFix to remove the infection.
Subscribe to:
Posts (Atom)