Chinese Internet Security Response Team (GMT +0800)

Really No Storm Codec on Your PC?

[Post on : April 9, 2008 20:13 | Category : Worm | by : smallmo] Reship : Original

Zhelatin gang has updated its tactic again today. We've received its new spams. In the latest spams, a malicious domain "sup<removed>eas.com" was contained. Besides spams, we also found this malicious domain was posted on lots of blogs.

Two files, "StormCodec.exe" and "StormCodec8.exe", will be downloaded. Kaspersky detects them as Email-Worm.Win32.Zhelatin.wt.

Here is the screenshot of this malicious site:

Open in new window

The part of the result of searching via Google:

Open in new window

Reference:

Arbor Networks: Busy Day - Kraken, New Storm Run, and MSFT Bulletins




Last modified by smallmo onApril 9, 2008 21:36

Betry Says : Email
April 26, 2009 00:21
Protection for your computer.
Search-and-destroy Antispyware is one of the best options available when you are searching for protection for your computer that you can trust. I know because I have tried many different types of scans in the past and the biggest difference I have found between them is the price. I found the antispyware solution from Search-and-destroy to be a great option that is affordable and easy to use. Visit http://www.Search-and-destroy.com to learn more about this scan and what it can do for you. If you are like me, you will be glad that you took the time to check it out.
billy Says :
June 19, 2008 07:58
Thanks i was infected with this problem
www.softhardware.co.uk
Omer Says : Homepage
May 5, 2008 14:55
Thanks for this useful explanation.
Omer KARADENIZ
http://www.omerkaradeniz.com
whocares Says :
April 11, 2008 12:00
screen shot of the spam, please?
Pages: 1/1 First page 1 Final page