Home Malware Programs Trojans Trojan.Win32.Gorshok.a

Trojan.Win32.Gorshok.a

Posted: December 18, 2007

Trojan.Win32.Gorshok.a is a Trojan name displayed in the deceptive warning message that is generated by the creators of the rogue IEDefender program. The alert with Trojan.Win32.Gorshok.a is intended to trick you into buying a commercial version of IEdefender.

The fake Trojan.Win32.Gorshok.a warning message is the following: "Critical System Error! Your browser was infected by Trojan.Win32.Gorshok.a". Once you click on the fake Trojan.Win32.Gorshok.a alert, you will be redirected to IEDefender's homepage where you will be forced to buy the full version of this rogue anti-spyware program.

Usually, Trojan.Win32.Gorshok.a is displayed by a Trojan Zlob, which downloads and installs itself together with fake video codec, often found in porno web sites. We recommend the immediate removal of Trojan Zlob, Trojan.Win32.Gorshok.a and IEdefender because they are a serious security risk to your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 blopenvxdt.dll
    2 cjvy.dll
    3 ecxwp.dll
    4 esent9.dll
    5 gqagksr.dll
    6 mlljh.dll
    7 msvideo.dll
    8 pmspl.dll
    9 popnetnpr.dll
    10 ssqppol.dll
    11 stream32a.dll
    12 ttvbonvgl.dll
    13 urqnomm.dll
    14 vtssp.dll
    15 websrc32.dll
    16 windivx.dll

Registry Modifications

  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}FF5137B5-C506-4D9B-8682-E0BE4675B8996F6D1C90-7BEE-4A15-8DAB-9C37A643FD3AD17CFF74-A19C-4C36-821A-E074E4F889CAb166be07-30a4-4d38-b781-44528a630706E856E05E-1B91-4339-9EFC-9A3308CB5491c4545fc9-26d0-4ccf-b4fb-728aed895dbd62EA9201-8CC7-4199-AC30-7744F836322E202EBB90-ABD4-46CC-BB5A-4F0ECC67B331F9EAAA11-DF98-4615-A2C7-7D03C86A6BE931E3F653-ED88-4355-B83E-FB263CD355E317A1DBB5-DAD8-4E78-BF7E-9BE4B965408BA19926CE-CA09-9EAE-7806-B9891B5461C8BBB05D9E-0297-404D-A6BF-D8F2876B84A643BA0532-0D69-458A-8C71-AD0F6AE70D19A8565FBC-8D53-4D4F-9BB0-CBC68A22B12669B98C68-D2B8-4A4E-9CB7-E85B6F3A7014B3E45A9B-7756-46A2-AB14-90175CD374F96A719349-BDF5-4268-9019-4ACA0C2562D26D64B03B-3B93-4AF2-BFC6-01264A4C7F2A15EB9F40-D775-4463-B75B-8687B3C66BB7

One Comment

  • Linda says:

    I need to remove this trojan, but I am on ss and cannot afford to purchase a program to do this. Is there anywhere I can find a free site.

Loading...