Monday, September 29, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus, Total Secure 2009

IE Defender/Files Secure/MalwareBell/IE Antivirus/Total Secure 2009 Codec has been update, it installs a file with semi-random filename composed from a dictionary:
gp, hj, at, ax, bs, vok

Possible filenames are:
gpatbs.dll, gpatvok.dll, gpaxbs.dll, gpaxvok.dll, hjatbs.dll, hjatvok.dll, hjaxbs.dll, hjaxvok.dll

It displays alert messages with popups that download Total Secure 2009:


It also drops Internet Shortcut on the desktop, Favorites, Start Menu: Free Porn.url , Free MP3 Search.url, Search Online.url and VIP Casino.url

Use SmitfraudFix to remove the infection.

Wednesday, September 24, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus, Total Secure 2009

IE Defender/Files Secure/MalwareBell/IE Antivirus/Total Secure 2009 Codec has been update, it installs a file with semi-random filename composed from a dictionary:
v, x, add, app, es, it

Possible filenames are:
vaddes.dll, vaddit.dll, vappes.dll, vappit.dll, xaddes.dll, xaddit.dll, xappes.dll, xappit.dll

It displays alert messages with popups that download Total Secure 2009:


It also drops a new Internet Shortcut on the desktop, Favorites, Start Menu: Free Porn.url with Free MP3 Search.url and VIP Casino.url

Use SmitfraudFix to remove the infection.

Tuesday, September 23, 2008

VideoAccessCodec (VAC)

VideoAccessCodec has been update, it installs the following files:

%WINDOWS%\dfmlxbpk???.dll (where ? is a random caracter)
%WINDOWS%\peltodgx.dll
%WINDOWS%\rwlfsdmk.dll
%WINDOWS%\onfwbsak.dll
%WINDOWS%\fbxrqtwn.exe
%WINDOWS%\e???.exe (where ? is a random caracter)

Use SmitfraudFix to remove the infection.

Monday, September 22, 2008

eAntivirusPro

eAntivirusPro is a fake security software (rogue) from the AntiMalware 2009, Micro Antivirus 2009, Vista Antivirus 2008, Antispyware 2008 XP, System Antivirus 2008, Internet Antivirus, Smart Antivirus 2009, MS Antivirus, Advanced Antivirus, Power Antivirus, XPert Antivirus family... that detects infections on a clean system.

AntiMalware 2009

AntiMalware 2009 is a fake security software (rogue) from the Micro Antivirus 2009, Vista Antivirus 2008, Antispyware 2008 XP, System Antivirus 2008, Internet Antivirus, Smart Antivirus 2009, MS Antivirus, Advanced Antivirus, Power Antivirus, XPert Antivirus family... that detects infections on a clean system.

IE Defender, Files Secure, Malware Bell, IE Antivirus, Total Secure 2009

IE Defender/Files Secure/MalwareBell/IE Antivirus/Total Secure 2009 Codec has been update, it installs a file with semi-random filename composed from a dictionary:
p, f, h, g, a, i

Possible filenames are:
pha.dll, phi.dll, pga.dll, pgi.dll, fha.dll, fhi.dll, fga.dll, fgi.dll

It displays alert messages with popups that download Total Secure 2009:


It also drops a new Internet Shortcut on the desktop: Free MP3 Search.url with VIP Casino.url

Use SmitfraudFix to remove the infection.

Saturday, September 20, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus, Total Secure 2009

IE Defender/Files Secure/MalwareBell/IE Antivirus/Total Secure 2009 Codec has been update, it installs a file with semi-random filename composed from a dictionary:
ha, p, re, gy, 32, ss

Possible filenames are:
hare32.dll, haress.dll, hagy32.dll, hagyss.dll, pre32.dll, press.dll, pgy32.dll, pgyss.dll

It displays alert messages with popups that download Total Secure 2009:


At this time, there is no more extra dropper (users64.dat) in this version. But things could change quickly.

Use SmitfraudFix to remove the infection.

Tuesday, September 16, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus, Total Secure 2009

IE Defender/Files Secure/MalwareBell/IE Antivirus/Total Secure 2009 Codec has been update, it installs a file with semi-random filename composed from a dictionary:
ajk, gj, pik, tbl, avn, i

Possible filenames are:
ajktbl.dll, ajkavn.dll, ajki.dll, gjtbl.dll, gjavn.dll, gji.dll, piktbl.dll, pikavn.dll, piki.dll

It displays alert messages with popups that download Total Secure 2009:


This infection runs a file from its resources, who modifies Avira Antivirus .ini file. This will prevent the Antivirus from scanning some infected files on the system. Easy, and powerful.

This new malware drops users64.dat in %SYSTEM% folder. This lib is executed by infected (patched) binaries in HKLM..Run or HKCU..Run keys.

Use SmitfraudFix to remove the infection.

Monday, September 15, 2008

Virus Response Lab 2009

A new rogue, Virus Response Lab 2009, has been released. This rogue is a new version of Antivirus Lab 2009. It is automatically installed by a Zlob trojan.



Use SmitfraudFix to remove the infection.

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\zafhemm.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8d332d3a-0114-4492-8521-c2b93b4db160}"="aspalathus"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.