<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : Trojan.Zlob</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/Trojan.Zlob/default.aspx</link><description>Tags: Trojan.Zlob</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Another poorly detected Trojan.Zlob</title><link>http://msmvps.com/blogs/hostsnews/archive/2007/09/24/1212284.aspx</link><pubDate>Mon, 24 Sep 2007 06:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1212284</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2007/09/24/1212284.aspx#comments</comments><description>&lt;p&gt;Landing on &amp;quot;&lt;em&gt;thesuperxxx(dot)com&lt;/em&gt;&amp;quot; the visitor is presented with a bogus &amp;quot;&lt;em&gt;Message Box Object error&lt;/em&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;img style="WIDTH:471px;HEIGHT:412px;" height="412" src="http://mvps.org/winhelp2002/blog/thesuperxxx.gif" width="471" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Clicking any of the above buttons leads to prompts &amp;quot;&lt;em&gt;You must install ... yada yada&lt;/em&gt;&amp;quot; to view the movie. There are 10 other sites involved in this latest Trojan.Zlob (Codec) infection. All these sites will be added to the next &lt;a class="" href="http://www.mvps.org/winhelp2002/hosts.htm" target="_blank"&gt;HOSTS file&lt;/a&gt; update.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/thesuperxxx2.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Running &amp;quot;&lt;em&gt;VideoAccessCodecInstall.exe&lt;/em&gt;&amp;quot; thru VirusTotal, you can see it is not very well detected. &lt;strong&gt;12.5%&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;&lt;img style="WIDTH:495px;HEIGHT:154px;" height="154" src="http://mvps.org/winhelp2002/blog/thesuperxxx3.gif" width="495" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;These type infections are becoming so rampant that they are now the&amp;nbsp;&lt;strong&gt;#1&lt;/strong&gt; detection at &amp;quot;&lt;a class="" href="http://www.microsoft.com/security/portal/" target="_blank"&gt;Microsoft Malware Protection Center&lt;/a&gt;&amp;quot; and that&amp;#39;s just the ones that Microsoft detects, which&amp;nbsp;Microsoft usually&amp;nbsp;does not detect very well&amp;nbsp;...&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/thesuperxxx1.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Did you know you can run the &amp;quot;&lt;a class="" href="http://www.microsoft.com/security/malwareremove/default.mspx" target="_blank"&gt;Malicious Software Removal Tool&lt;/a&gt;&amp;quot; (MSRT) anytime? Usually you only see the &amp;quot;Quick Scan&amp;quot; from Windows Update monthly, however you can get (mrt.exe) to run a &amp;quot;&lt;em&gt;Extended Scan&lt;/em&gt;&amp;quot;. Simply locate &amp;quot;&lt;em&gt;Windows\System32\MRT.exe&lt;/em&gt;&amp;quot;, right-click and select &amp;gt; SendTo &amp;gt; Desktop (create shortcut). Next right-click the new icon on your Desktop and select: Properties. From there you can change the &amp;quot;Target&amp;quot; to a desired option.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;/Q&lt;/strong&gt; or /quiet - Use quiet mode. This option suppresses the user interface of the tool. &lt;br /&gt;&lt;strong&gt;/?&lt;/strong&gt; - Display a dialog box that lists the command-line switches. &lt;br /&gt;&lt;strong&gt;/N&lt;/strong&gt; - Run in detect-only mode. In this mode, malicious software will be reported to the user but will not be removed. &lt;br /&gt;&lt;strong&gt;/F&lt;/strong&gt; - Force an extended scan of the computer. &lt;br /&gt;&lt;strong&gt;/F:Y&lt;/strong&gt; - Force an extended scan of the computer and automatically clean any infections found.&lt;/p&gt;
&lt;p&gt;An undocumented switch that I use ... if you have more than one hard drive (or partition) is to add the drive letter if you only want to scan one drive. Otherwise MSRT will scan all drives ... and it takes a while ... more info &lt;a class="" href="http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B890830" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;C:\Windows\System32\MRT.exe /f D:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Where &amp;quot;/f&amp;quot; runs a extended scan and &amp;quot;D:&amp;quot; scan only drive D.&amp;nbsp;The results are recorded here: &amp;quot;&lt;em&gt;Windows\Debug\mrt.log&lt;/em&gt;&amp;quot;.&lt;br /&gt;Folks this is not a replacement for your Antivirus, simply another (free) tool you can use if you suspect you are infected.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: I ran the above and it did &lt;strong&gt;NOT&lt;/strong&gt; detect: &amp;quot;&lt;em&gt;VideoAccessCodecInstall.exe&lt;/em&gt;&amp;quot; (noted above)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1212284" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Trojan.Zlob/default.aspx">Trojan.Zlob</category></item></channel></rss>