update.microsoft.com and then offers a codec (fake, obviously!) for download. Here are some of the screenshots of fake player:


The codec is named as Megazcodec and is hosted at
http://megazcodec.com. Megazcodec is yet another Zlob/DNSChanger variant; however it is not well detected as of now. The VirusTotal report is as shown:File megazcodec.v3.104.exe
AntiVir 7.8.1.28 - TR/Dropper.Gen
BitDefender - Trojan.DNSChanger.VD
Ikarus - Win32.SuspectCrc
Sunbelt 3.1.1610.1 - Media Code, Inc (v)
Webwasher-Gateway - Trojan.Dropper.GenComplete VirusTotal scan result can be found here.
0 comments:
Post a Comment