Saturday, July 12, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: ie, iexp, inte, fltr, fl, _f

Files could look like: iefltr.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Wednesday, July 9, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: nav, nvg, nv, filter, flt, f

Files could look like: nvgflt.dll, nvgf.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Monday, July 7, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: eps, epson, eps, drv, bho, 32

Files could look like: epsdrv.dll, epsondrv.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Sunday, July 6, 2008

Fake Cracks/Keygen Video

Following the serie Zlob for dummies, MAD made a video of the consequences of running a Trojan from a Fake Crack Blog. (MAD Article)

Friday, July 4, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\hkushdr.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d1577581-2ed7-469f-99b1-72c1339e0ee0}"="doctordom"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: avg, ant, avira, safe, _sr, _ss

Files could look like: avg_sr.dll, avirasafe.dll, ant_ss.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Thursday, July 3, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: agin, snop, wdol, _bho, tas, o32

Files could look like: agintas.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Wednesday, July 2, 2008

IE Defender, Files Secure, Malware Bell, IE Antivirus

IE Defender/Files Secure/MalwareBell/IE Antivirus Codec has been update, it installs files with semi-random filenames, composed from fragment words: sl, ps, dig, a32, onyx, arox

Files could look like: slarox.dll ...

and displays alert messages with popups:


Use SmitfraudFix to remove the infection.

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\blbpeoy.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ecc974ae-6ede-44a2-90da-93b996d8eaf8}"="frizzed"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.

Tuesday, July 1, 2008

Zlob for dummies.

MAD wrote a topic (french) about Zlob infections.

The second part is less technical and speaks about infected victims. Some users have irresponsible comportments that lead to infection. This can sometimes be resumed as: I have an Antivirus suite, I'm safe still vulnerable.


Image Copyright: IKARUS Security Software GmbH.