Help - Search - Members - Calendar
Full Version: Warning! Don't download and run zCodec!
Quest For More Glory forums > General > Hardware, Software, Tips and Tweaks
DeadPoolX
Fresh off SlashDot (and off my Google homepage) comes a notice about a new piece of software that supposedly offers up to 40% better video quality, and boosts audio quality as well. Whether or not it really does that is moot, since in reality, this program is adware that downloads trojans, rootkits, and other malicious software.

Here's what part of the article--and system security outfit, Panda Software--says:
QUOTE
Panda's advisory last week revealed that the 100KB file is in fact adware, which "downloads and runs files, changes the DNS configuration and monitors accesses to several adult websites". zCodec, formally known as Adware/ZCodec or Adware/EMediacodec, affects most versions of Windows and was first detected last week, Panda said.

When run, the program alters the system's DNS configuration in order to divert traffic to DNS servers of its choice, a technique sometimes used as part of a phishing scam or to rack up clicks for advertising schemes.

zCodec also accesses a particular IP address to randomly select and download one of a collection of files. The files that could be downloaded include Ruins.MB, a Trojan horse that uses rootkit techniques to conceal itself, Panda said. zCodec could also download an online casino program.

A second file launches every time the user starts Internet Explorer and monitors Web usage. Panda said its software can remove zCodec.


So, chances are that second file wouldn't run if you use Firefox or Opera, but the rest of zCodec is disturbing, especially since the program (and website) passes itself off as a freely legal and safe download. If you're interested in reading the entire article at Techworld, then go here: Codec Promises Video, Delivers Nasties.

Anyway, that's about it. I saw this and thought that everyone here should be alerted about this program. I figure most everyone here keeps pretty safe Internet habits, so perhaps this warning wasn't even really necessary. Regardless, I felt it'd be good to have here. smile.gif
Paladin Wizard
This is why people should stick with FFDShow or FFDShow based packs like CCCP. biggrin.gif
Almirena
Thanks for posting, DPX. I still find myself being foolishly trusting when I look at downloadable programmes - not in terms of downloading the material, but in terms of thinking first, "Oh, now nice of someone to create something for free download, may heaven rain blessings upon their head", and then thinking, "Haaaang on..." and hoping it's not a sneaky way to attempt to use people rather than help people.

So my caution is secondary to my instinctive wish to trust. <sigh> However, it's so rapid a process that it takes less than a second. Unfortunately, we all have to had that "Haaaang on" reaction in the Brave New Internet World in which we live.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.