tag:blogger.com,1999:blog-73373697900428721902008-07-24T23:03:07.734+02:00S!Ri.URZS!Rinoreply@blogger.comBlogger152125tag:blogger.com,1999:blog-7337369790042872190.post-44493530228881165312008-07-24T23:02:00.000+02:002008-07-24T23:03:07.752+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: dom, hom, sof, ie, bho, iebho<br /><br />Files could look like: domie.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-79711513967750436182008-07-23T13:32:00.001+02:002008-07-23T13:32:55.073+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: bho, bho2, ie, ext, extn, _e<br /><br />Files could look like: bho2extn.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-27130641679152616092008-07-22T12:08:00.001+02:002008-07-22T12:08:44.591+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">uszhv.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{629340b5-8df6-4211-9245-a86563a35792}"="cramping"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-12936215143430165122008-07-20T22:13:00.000+02:002008-07-20T22:14:31.805+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: ie, iex, IE_, filter, flt, fil<br /><br />Files could look like: iefilter.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-42068888335242581032008-07-20T18:11:00.009+02:002008-07-20T23:03:35.271+02:00MO5.com in danger.A post in French, for once, about one of my hobby (vintage 8-bit computers): A non-profit association, <a href="http://mo5.com/">MO5.com</a>, is in danger. A collection of 30.000 items composed of old school computers might be scattered or disappear.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://siri.urz.free.fr/Bitmaps/Misc/MO5.COM_Local-02.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 300px; height: 195px;" src="http://siri.urz.free.fr/Bitmaps/Misc/MO5.COM_Local-02.jpg" alt="" border="0" /></a>Suite à la visite d'une commission de sécurité , les locaux où sont entreposés plus de 30.000 pièces (ordinateurs, consoles, magazines, CD et diverses geekeries) ont été jugés dangereux.<br />Cette commission demande le départ de cette fabuleuse collection, seulement l'association n'a pas les moyens logistiques et financier pour rebondir.<br /><br />C'est pourquoi MO5.COM demande un coup de main à tous les geeks/geekettes de France, pour sauver de l'anéantissement tout ce travail.<br /><br />Pour plus d'informations, rendez-vous sur leur <a href="http://soutien.mo5.com/">lettre de soutien</a>.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-34017169865949325082008-07-19T23:45:00.000+02:002008-07-19T23:46:15.601+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">xevhbpw.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{201a14d7-b5b4-422c-816f-5f2a1e92e0e7}"="incorrectnesses"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-84741657207006546982008-07-19T16:12:00.002+02:002008-07-19T16:13:16.161+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: tb, toolbar, tbr, srch, s, sch<br /><br />Files could look like: toolbars.dll, tbrsrch.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-88636785667924511282008-07-12T17:47:00.001+02:002008-07-12T17:47:57.989+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: ie, iexp, inte, fltr, fl, _f<br /><br />Files could look like: iefltr.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-68353763432792854062008-07-09T08:48:00.001+02:002008-07-09T08:49:39.602+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: nav, nvg, nv, filter, flt, f<br /><br />Files could look like: nvgflt.dll, nvgf.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-30121210934193609692008-07-07T22:15:00.001+02:002008-07-07T22:17:10.599+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: eps, epson, eps, drv, bho, 32<br /><br />Files could look like: epsdrv.dll, epsondrv.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-55752871983119379112008-07-06T23:50:00.006+02:002008-07-07T00:19:50.648+02:00Fake Cracks/Keygen VideoFollowing the serie <a href="http://siri-urz.blogspot.com/2008/07/zlob-for-dummies.html">Zlob for dummies</a>, MAD made a <a href="http://secuboxlabs.fr/archives/computertoday.html">video</a> of the consequences of running a Trojan from a Fake Crack Blog. (<a href="http://secubox.aldria.com/topic-2393.html">MAD Article</a>)S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-4239427511701787442008-07-04T23:44:00.000+02:002008-07-04T23:45:18.685+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">hkushdr.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{d1577581-2ed7-469f-99b1-72c1339e0ee0}"="doctordom"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-42399820004357006122008-07-04T20:08:00.002+02:002008-07-04T20:12:50.220+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: avg, ant, avira, safe, _sr, _ss<br /><br />Files could look like: avg_sr.dll, avirasafe.dll, ant_ss.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-88551527468401231472008-07-03T10:46:00.001+02:002008-07-03T10:46:53.969+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: agin, snop, wdol, _bho, tas, o32<br /><br />Files could look like: agintas.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-89476874474418306742008-07-02T13:36:00.001+02:002008-07-02T13:37:35.504+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: sl, ps, dig, a32, onyx, arox<br /><br />Files could look like: slarox.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-13025704353749016662008-07-02T13:23:00.001+02:002008-07-02T13:23:55.303+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">blbpeoy.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{ecc974ae-6ede-44a2-90da-93b996d8eaf8}"="frizzed"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-77034410830623213482008-07-01T09:01:00.005+02:002008-07-04T21:48:05.187+02:00Zlob for dummies.MAD wrote a topic (french) about <a href="http://secubox.aldria.com/topic-2388.html">Zlob infections</a>.<br /><br />The second part is less technical and speaks about infected victims. Some users have irresponsible comportments that lead to infection. This can sometimes be resumed as: <span style="font-style: italic;">I have an Antivirus suite, I'm <s>safe</s> still vulnerable</span>.<br /><br /><a href="http://siri.urz.free.fr/Bitmaps/Misc/av_industry.gif"><img src="http://siri.urz.free.fr/Bitmaps/Misc/av_industry_mini.gif" border="0" /></a><br /><span style="font-size:78%;">Image Copyright: IKARUS Security Software GmbH.</span>S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-42438363597578942722008-06-23T23:36:00.000+02:002008-06-23T23:37:55.576+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: opus, sigma, nada, 64, 32, 16<br /><br />Files could look like: sigma64.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-26727509595880551652008-06-23T23:01:00.000+02:002008-06-23T23:02:36.511+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">sgntu.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{c27abdde-8a43-4a7f-81c0-3fc3c952284f}"="chicot"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-39890409923153072832008-06-19T12:08:00.003+02:002008-06-19T12:26:44.318+02:00Zlob, fake downloadFake site proposing <a href="http://siri-urz.blogspot.com/2008/06/zlob-fake-download.html">software download</a> (or Keygen/Crack) installing a Zlob Malware.<br /><br /><img src="http://siri.urz.free.fr/log/misc/FakeSoftwareInstaller2.png" border="0" />S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-45004882540676294752008-06-18T15:29:00.000+02:002008-06-18T15:31:10.760+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: da, co, i, def, pol, ni<br /><br />Files could look like: dadef.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-20889702565167765792008-06-18T00:07:00.000+02:002008-06-18T00:08:14.739+02:00ZlobZlob fake codec has been update. It drops the following file:<br /><br />%SYSTEM%\<span style="font-weight:bold;">funfsnv.dll</span><br /><br />[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<br />"{99f8405b-63d1-421a-83bb-7b4b0642ac28}"="eulogical"<br /><br />It also installs Toolbar, BHO, <a href="http://siri-urz.blogspot.com/2008/06/antispycheck-210.html">Antispycheck Rogue</a> software...<br /><br /><a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> removes the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-79212554558890774812008-06-17T13:40:00.004+02:002008-06-17T13:52:40.842+02:00IE Defender, Files Secure, Malware Bell, IE Antivirus<a href="http://siri-urz.blogspot.com/2007/11/ie-defender.html">IE Defender</a>/<a href="http://siri-urz.blogspot.com/2007/11/files-secure.html">Files Secure</a>/<a href="http://siri-urz.blogspot.com/2008/04/malware-bell.html">MalwareBell</a>/<a href="http://siri-urz.blogspot.com/2008/04/ie-antivirus.html">IE Antivirus</a> Codec has been update, it installs files with semi-random filenames, composed from fragment words: x, c, s, edif, osys, ecol, ns, pd, gd, a, o, y<br /><br />Files could look like: cosysnsy.dll, xecolgda.dll ...<br /><br />and displays alert messages with popups:<br /><img src="http://siri.urz.free.fr/log/misc/IEDefenderFakeAlert4.jpg"><br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-80921119323648026902008-06-16T23:51:00.001+02:002008-06-16T23:51:55.832+02:00VideoAccessCodec (VAC)<a href="http://siri-urz.blogspot.com/2008/04/videoaccesscodec-vac.html">VideoAccessCodec</a> has been update, it installs the following files:<br /><br />%WINDOWS%\<span style="font-weight:bold;">ksendlbt???.dll</span> (where ? is a random caracter)<br />%WINDOWS%\<span style="font-weight:bold;">vrmdtneg.dll</span><br />%WINDOWS%\<span style="font-weight:bold;">xvorfwbd.dll</span><br />%WINDOWS%\<span style="font-weight:bold;">wpvmqosg.dll</span><br />%WINDOWS%\<span style="font-weight:bold;">neltabxw.exe</span><br />%WINDOWS%\<span style="font-weight:bold;">e???.exe</span> (where ? is a random caracter)<br /><br />Use <a href="http://siri.urz.free.fr/Fix/SmitfraudFix.php">SmitfraudFix</a> to remove the infection.S!Rinoreply@blogger.comtag:blogger.com,1999:blog-7337369790042872190.post-54841125769727940062008-06-16T13:19:00.006+02:002008-06-16T13:48:14.600+02:00Zlob, fake downloadZlob infections are related to p0rn sites !<br />This used to be true but it is not anymore. After <a href="http://siri-urz.blogspot.com/2008/04/videoaccesscodec-vac.html">Fake Codec Errors</a> , <a href="http://siri-urz.blogspot.com/2008/05/videoaccesscodec-vac_16.html">Fake Flash Errors</a>, <a href="http://siri-urz.blogspot.com/2007/12/flash-player-incorrect-version.html">Fake Flash Version</a>, <a href="http://www.trustedsource.org/TS?do=threats&amp;subdo=blog&amp;id=37">Faked MP3 Download</a>.<br />Zlob infections familly (Rogue installer Antispycheck/IEAntivirus, DNS Changer, VAC) is also spread on Fake Cracks/Warez Blogs or Fake Softwares Downloads WebSites.<br /><br /><img src="http://siri.urz.free.fr/log/misc/FakeSoftwareInstaller.png" border="0" /><br /><br />Notice the "*100% checked by Antivirus" comment ;)S!Rinoreply@blogger.com