From: "Peter Foldes" <***@hotmail.com>
| Before anybody else jumps on me. I did not open the link. Someone from microsoft
| Hungary put out the alarm on this post which was also posted there and in all foreign
| groups. I just tried to warn others and unfortunately in my haste without thinking I
| included the original link in my post.
| Many think I opened the link which I did not. I never had any virus ,malware,trojan
| since I have been posting in the Microsoft forums for the last 15 yrs. So I made an
| error in posting and everyone seems to think I opened the link and that is how I found
| it. Sheeees.
| Thank a bunch to those people
| --
| Peter
I did, but NOT with a browser ;-)
I easily found the IFrame and file intended to be downloaded. I recognized the Social
Engineering in the post and was in the process of analizing it when you replied.
It's a fake codec called LPVideoPlugin and installs a BHO as...
C:\Program Files\LPVideoPlugin\5378.exe
C:\WINDOWS\system32\LPVideo.dll
HKLM\Software\Classes\AppID\{B90618AA-A0BF-41EE-8BDA-DC965B49042D}
HKLM\Software\Classes\AppID\LPVideo.DLL
HKLM\Software\Classes\LPVideo.XMLDOMDocumentEventsSink.1
HKLM\Software\Classes\LPVideo.XMLDOMDocumentEventsSink.1\CLSID
HKLM\Software\Classes\LPVideo.XMLDOMDocumentEventsSink
HKLM\Software\Classes\LPVideo.XMLDOMDocumentEventsSink\CLSID
HKLM\Software\Classes\LPVideo.XMLDOMDocumentEventsSink\CurVer
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}\ProgID
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}\VersionIndependentProgID
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}\Programmable
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}\InprocServer32
HKLM\Software\Classes\CLSID\{BEDA34FB-740D-4975-95DD-003A068CF999}\TypeLib
HKLM\Software\Classes\LPVideo.LPVideoPlugin.1
HKLM\Software\Classes\LPVideo.LPVideoPlugin.1\CLSID
HKLM\Software\Classes\LPVideo.LPVideoPlugin
HKLM\Software\Classes\LPVideo.LPVideoPlugin\CLSID
HKLM\Software\Classes\LPVideo.LPVideoPlugin\CurVer
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}\ProgID
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}\VersionIndependentProgID
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}\Programmable
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}\InprocServer32
HKLM\Software\Classes\CLSID\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}\TypeLib
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\{724B80DE-D97A-4384-8960-6AF64CE5BBB3}
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}\1.0
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}\1.0\FLAGS
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}\1.0\0
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}\1.0\0\win32
HKLM\Software\Classes\TypeLib\{A3433B72-420B-4074-81AA-BD253532C230}\1.0\HELPDIR
HKLM\Software\Classes\Interface\{F19273AA-BD78-4EEA-A783-6177F6A1A547}
HKLM\Software\Classes\Interface\{F19273AA-BD78-4EEA-A783-6177F6A1A547}\ProxyStubClsid
HKLM\Software\Classes\Interface\{F19273AA-BD78-4EEA-A783-6177F6A1A547}\ProxyStubClsid32
HKLM\Software\Classes\Interface\{F19273AA-BD78-4EEA-A783-6177F6A1A547}\TypeLib
HKLM\Software\Classes\Interface\{F9713375-EC34-4638-8176-7884D5CEF112}
HKLM\Software\Classes\Interface\{F9713375-EC34-4638-8176-7884D5CEF112}\ProxyStubClsid
HKLM\Software\Classes\Interface\{F9713375-EC34-4638-8176-7884D5CEF112}\ProxyStubClsid32
HKLM\Software\Classes\Interface\{F9713375-EC34-4638-8176-7884D5CEF112}\TypeLib
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp