Page 1 of 1

newest nasty adware/spyware

Posted: Tue Sep 05, 2006 1:38 pm
by DW_Wraith
http://theinquirer.net/default.aspx?article=34156

SECURITY OUTFIT Panda software says that a video codec which is appearing in the wild offering "up to 40 percent better video quality" is a nasty bit of adware.

zCodec is freely available online and can be downloaded from http://www.zcodec.com/. The site uses images from flicks Sin City and Pulp Fiction to claim boosts to audio as well as video quality.

It claims to be a multimedia compressor/decompressor which registers into the Windows collection of multimedia drivers and integrates with any application using DirectShow and Microsoft Video for Windows.

The only thing that suggests that there might be something wrong is a typo on the front page which links to its "terms of use" page. Still, you get that with the big jobs.

However, Panda said that the ‘codec’ downloads and runs files, changes the DNS configuration and monitors accesses to several adult websites.

It is known as adware/ZCodec or Adware/EMediacodec and affects most versions of Windows. Some of the files that the adware has been downloading are particularly nasty, including a rootkit called Ruins.MB, which does what it says on the tin.

Posted: Tue Sep 05, 2006 8:02 pm
by Namu
Thanks for looking out for us Wraith!

Posted: Thu Sep 07, 2006 10:41 am
by kaeolian
Good looking out. Its a shame there is stuff like this out there, its what will eventualy lead to the internet beingg moderated in its entirety.

Posted: Thu Sep 07, 2006 2:28 pm
by Gorzakk
Thanks for the info Wraith. I hate this kind of crap. BTW, does anyone know of a good free firewall that can be used on a PC that has multiple login accounts? I hate this mcafee rubbish.

Posted: Thu Sep 07, 2006 3:42 pm
by kaeolian
http://www.clandw.com/modules.php?name= ... opic&t=491 have a look in there Gorz :drunken:

Posted: Fri Sep 08, 2006 5:30 pm
by DW_Wraith
I can't beleive a major company's website has a tojan that has been there for some time and probably is still there.

http://www.betanews.com/article/Samsung ... 1157743771

Samsung Web Site Infecting Visitors

Security firm Websense warned this week that attackers had apparently broke into the Web site of telecommunications company Samsung, infecting certain portions of the site with a Trojan horse. The firm said it was likely that the site had been infected for some time.

"The most current code, which is still available for download, is a Trojan Horse that attempts to disable anti-virus programs, modify registry keys, download additional files, and log keystrokes when connecting to banking websites," Websense said in an advisory.

Posted: Fri Sep 08, 2006 7:25 pm
by DW_Hornet
Ok who stole wraiths forum account?

Posted: Fri Sep 08, 2006 9:30 pm
by DW_e_aLpHa
NOTE: Not meaning it has to be for 'good' Neverminding that .. Is art! IMPOV

dont you love and admire the complexity of such cute tiny little pieces of programming ? -- I call it art! .. Because everyone of them reflects a big expense of deep thoughts , and ideas that make possibilities become the most real and usable instrument wich is then able to bring the results of the desire that originally created them - Deeply marvellous dont you agree ?..-- but people call it 'trojan' ..

NOTE: Not meaning it has to be for 'good' Neverminding that .. Is art! IMPOV