3Spyberus jpg
jahewi.nl
3Spyberus jpg
375px x 500px | 12.70kB

[source page]

jahewi july 4 2006

obj14geo14pg1p20 jpg
jahewi.nl
obj14geo14pg1p2​0 jpg
345px x 472px | 29.80kB

[source page]

As I already blogged here English and here Dutch these fake codecs work on our natural curiousity Until now I didn t came across a fake codec that downloaded itself

obj23geo23pg1p20 jpg
jahewi.nl
obj23geo23pg1p2​0 jpg
376px x 485px | 35.40kB

[source page]

The image on the right tells it s tale both Spyberus and Ewido which in my case are installed sometimes to watch the secret installation of the trojans and other malware will show

eula2 jpg
jahewi.nl
eula2 jpg
393px x 503px | 61.50kB

[source page]

Okay back to the events on hand if you would decide to take your changes and install the fake codec

SBR VirusBurstDetailsS jpg
jahewi.nl
SBR VirusBurstDetai​lsS jpg
527px x 533px | 48.90kB

[source page]

Details of the installed malware

gg44 2s jpg
jahewi.nl
gg44 2s jpg
422px x 600px | 20.10kB

[source page]

WRONG Clicking the movie sents you straight to the installation page of a new Fake Codec called CodecPretty

18Infected jpg
jahewi.nl
18Infected jpg
375px x 500px | 31.90kB

[source page]



siteS jpg
jahewi.nl
siteS jpg
360px x 500px | 17.30kB

[source page]



AntiVermins install1 jpg
jahewi.nl
AntiVermins install1 jpg
393px x 503px | 36.10kB

[source page]



PlayerCodec SiteS jpg
jahewi.nl
PlayerCodec SiteS jpg
375px x 500px | 22.00kB

[source page]

At this time most fake codecs are already installing their load of trojans

13SpyberusCleanAgain jpg
jahewi.nl
13SpyberusClean​Again jpg
375px x 500px | 18.00kB

[source page]



imgindexs jpg
jahewi.nl
imgindexs jpg
412px x 550px | 27.00kB

[source page]

Restoring a Canned Tree

17dlPleks jpg
jahewi.nl
17dlPleks jpg
376px x 500px | 15.70kB

[source page]



eula1 jpg
jahewi.nl
eula1 jpg
393px x 503px | 66.50kB

[source page]



AntiVermins site1S jpg
jahewi.nl
AntiVermins site1S jpg
360px x 500px | 23.60kB

[source page]

Taskbar icon

SBRCodec2S jpg
jahewi.nl
SBRCodec2S jpg
410px x 518px | 41.50kB

[source page]



5 SpamClickedS jpg
jahewi.nl
5 SpamClickedS jpg
504px x 700px | 55.40kB

[source page]

Now then what would happen if you want to get rid of your Spam by clicking Spam protection

IEHijackS jpg
jahewi.nl
IEHijackS jpg
375px x 500px | 29.50kB

[source page]



SBRCodec3S jpg
jahewi.nl
SBRCodec3S jpg
412px x 520px | 19.90kB

[source page]



eula1 jpg
jahewi.nl
eula1 jpg
393px x 503px | 67.70kB

[source page]



From Yahoo Image Search: 'jahewi'
Sat Mar 13 13:19:26 2010 [ refresh local cache ]