Saturday, October 28, 2006

Videokeycodec 11.0

I am a software technician for a major computer corporation. Within the past two days, I have had calls from at least two customers regarding the following malware infection. Googling the main application, Videokeycodec 11.0 yeilded no results, so I thought I should make my experience available to the general public.

DISCLAIMER: This article is based soley on my own experience with removing this infection. So far it appears to be successful.

Symptoms:
  • Yellow triangular icon in system tray, giving frequent notification that "Your Computer Is Infected"
  • Clicking on this notification is reported to have opened porn sites in internet explorer.
  • The following items are present in Add/Remove Programs:
Public Messenger (usually version 2.08)
IE Security Update
Videokeycodec 11.0

Cause:
  • Unconfirmed, but may come from opening certain messages on Myspace. I've had a report that the pogram opened itself when the recipiant opened the message. This also appears to be similar to one of the myriad "download this codec to watch this free smutty video" trojans out there.
Removal:
  1. Boot to safe mode with networking (tap the F8 key repeatedly after starting the computer, select "safe mode with networking" from the Advanced Options menu that appears.)
  2. Go to Start>My Computer>Program Files
  3. Delete the folder named Videokeycodec.
  4. Empty your recycle bin
  5. Go to Start>Control Panel>Add/Remove Programs
  6. Remove Public Messenger, IE Security Update, and Videokeycodec 11.0 (NOTE: you will get an error message stating that the program appears to have been uninstalled already, and asking if you would like to remove it from the add/remove programs list. Click yes.)
  7. Reset your Internet Explorer settings to defaults, as detailed here
  8. Update the definitions in your antivirus and antispyware applications. If you do not have any, visit free.grisoft.com to get some free (and effective) software.
  9. Reboot your computer in normal mode. Your computer should now be clean, but it would be a good idea to run a scan for other spyware, as this does appear to be a trojan.

1 comment:

Anonymous said...

Thanks So much! You saved my computer!