It displays fake alert to install IEDefender Rogue and Hijacks google pages with an alert and a malware p0rn link.
Tuesday, October 30, 2007
Multimedia Decoder
Multimedia Decoder is another fake codec installing malware.
It displays fake alert to install IEDefender Rogue and Hijacks google pages with an alert and a malware p0rn link.


It displays fake alert to install IEDefender Rogue and Hijacks google pages with an alert and a malware p0rn link.
Libellés :
FakeSiteMessage,
IEDef,
Malware,
ScreenShots
Wednesday, October 24, 2007
VirusRay 3.8
A new Rogue has been released: VirusRay.
This rogues looks like: Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.
This rogues looks like: Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.
Libellés :
Rogues,
ScreenShots
Saturday, October 6, 2007
Tuesday, October 2, 2007
Spyware.WinAntiVirus
A new version of Spyware.WinAntiVirus has been released.
HijackThis symptoms:
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [DoNotDelete] C:\WINDOWS\System32\explore.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [DoNotDelete] C:\WINDOWS\System32\explore.exe
O4 - Startup: info.exe
O4 - Startup: system.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: info.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - AppInit_DLLs: C:\WINDOWS\System32\sulimo.dat
HijackThis symptoms:
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [DoNotDelete] C:\WINDOWS\System32\explore.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [DoNotDelete] C:\WINDOWS\System32\explore.exe
O4 - Startup: info.exe
O4 - Startup: system.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: info.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - AppInit_DLLs: C:\WINDOWS\System32\sulimo.dat
Libellés :
Malware,
ScreenShots
Sunday, September 30, 2007
AntiVirGear 3.8
A new version of the Rogue AntiVirGear has been released.
This rogues looks like: VirusProtectPro , SpyDown, SpywareQuake.
This rogues looks like: VirusProtectPro , SpyDown, SpywareQuake.
Libellés :
Rogues,
ScreenShots
Saturday, September 29, 2007
Monday, September 24, 2007
Zlob Hijacks Winsock LSP
Zlob Malware is Hijacking Winsock.
All begins with the installation of the fake software: Video ActiveX Enhancement 2.07 which installs: AntiVirGear 3.7, BHO, Alerts Popups, IEToolBar...
Now 2 files laf?.dll and laf?.ini are dropped in %SYSTEM% folder (where ? is a number from 1 to 5). Files are detected as Trojan-Downloader.Win32.Agent.doe by Kaspersky Antivirus.
HijackThis Symptoms:
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
Use LSPFix to remove the files. (Bleeping Computer Guide)
All begins with the installation of the fake software: Video ActiveX Enhancement 2.07 which installs: AntiVirGear 3.7, BHO, Alerts Popups, IEToolBar...
Now 2 files laf?.dll and laf?.ini are dropped in %SYSTEM% folder (where ? is a number from 1 to 5). Files are detected as Trojan-Downloader.Win32.Agent.doe by Kaspersky Antivirus.
HijackThis Symptoms:
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\laf1.dll
Use LSPFix to remove the files. (Bleeping Computer Guide)
Wednesday, September 19, 2007
AntiVirGear 3.7
After the release of different version of VirusProtectPro (3.3 to 3.6) the rogue mutates to AntiVirGear 3.7. A modified version of SpyDown, SpywareQuake.
Libellés :
Rogues,
ScreenShots
Monday, July 2, 2007
VirusProtectPro 3.3
VirusProtectPro Rogue, a modified version of SpyDown, SpywareQuake.
Libellés :
Rogues
Tuesday, May 22, 2007
Privacy Danger Desktop Hijack
Privacy Danger is a componant of NewMediaCodec/VideoAccessCodec (VideoCach), a fake codec that displays alerts, Rogue popups, installs a BHO...
Desktop background modified:
Desktop background modified:
Libellés :
DesktopHijack,
ScreenShots
Subscribe to:
Posts (Atom)