Removing a fake codec pack trojan from your PC
A trojan posing as a video codec lures users with promises of playing obscure file formats, then quietly opens a backdoor in the background. The scheme is older than the NBN rollout in regional New South Wales, yet it still circulates aggressively on Australian download portals and peer-to-peer networks. Once installed, the malicious bundle drops additional payloads, hijacks browser settings and sometimes disables security software.
The damage rarely announces itself with dramatic pop-ups. More often, victims in Sydney and Melbourne notice sluggish systems, mysterious outbound network traffic and unfamiliar processes in Task Manager. Some variants steal credentials stored in browsers, while others enlist the machine into a botnet used for distributed denial attacks. Recognising the pattern early makes the difference between a quick cleanup and a full system rebuild.
This guide walks through a practical, repeatable process suitable for Windows 10 and Windows 11 machines commonly used across Australian homes and small offices. It draws on standard procedures documented by cybersecurity analysts and combines them with local context about how these threats reach our region.
If you suspect your PC is hosting one of these trojans, the steps below assume no advanced technical background. They focus on Safe Mode cleanup, manual removal of stubborn components and the verification stages that prove the infection is gone. Treat the instructions as a checklist rather than a rigid script.
How the fake codec trojan reaches Australian computers
The most frequent delivery method is a bundled installer pretending to be a "codec pack" needed to play a specific video file. Users searching for foreign-language films, classic sporting footage or older Flash content stumble onto forums and free-streaming sites popular with Australian audiences. The download page insists the video will not play without the offered pack, and the installer carries a familiar brand to lend credibility.
Some variants piggyback on legitimate software hosted on third-party mirrors. A user looking for VLC or K-Lite may end up on a domain that looks almost identical, but bundles the genuine program with hidden payloads. Others spread through malicious email attachments that reference local events, such as AEST scheduling notices for sporting fixtures or parcel delivery scams impersonating Australia Post. Many of these samples fall under the broader classification covered by the potentially unwanted program category.
Once executed, the installer drops files in AppData, ProgramData and the Windows Registry. Persistence is usually achieved through Run keys, scheduled tasks or, in the more advanced samples, a Windows service that survives reboots. The trojan then phones a command-and-control server, often hosted in jurisdictions outside the reach of the ACSC.
Recognising the telltale symptoms
| Symptom |
Where to check |
What it indicates |
| Unfamiliar "codec" entries in Programs |
Control Panel → Programs |
Trojan survived cleanup attempts |
| Random outbound traffic on port 443 or 8080 |
Resource Monitor or GlassWire |
Active command-and-control beaconing |
| Browser redirects to shady search portals |
Chrome/Edge extension list |
Hijacker module still active |
| Disabled Windows Defender after reboot |
Security Center settings |
Defender tampering service running |
| Unknown scheduled tasks at odd hours |
Task Scheduler library |
Persistence mechanism installed |
The comparison above reflects patterns seen in samples reported by Australian small businesses between Perth and Brisbane. Most home users only spot two or three of these signs before reaching for help, and that is fine. Even partial evidence justifies moving to the next stage.
Preparing the system before you touch the infection
Before deleting files, take a precautionary snapshot of the situation. Disconnect from the internet to cut the command-and-control channel, then back up documents to an external drive that you will not plug in again until it has been scanned. Cloud services such as OneDrive or Google Drive remain convenient for users in Adelaide and Hobart, but only sync after the local machine is clean.
Reboot into Safe Mode with Networking. This stops most persistence mechanisms from loading and gives the cleanup a fighting chance. On Windows 11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart. Choose option 4 or 5 depending on whether you still need network access for tool downloads.
At this stage, gather your cleanup utilities on a separate USB drive. A reputable offline antivirus scanner, a portable version of Autoruns and a recovery tool such as Recuva can be staged in advance. Having everything ready prevents the situation where a partial cleanup strands you without tools. For users who prefer guided walkthroughs, the for Windows section covers preparation routines tailored to Australian ISP environments such as Telstra and Optus.
The cleanup process step by step
Open Task Manager and end suspicious processes first. Focus on entries with no publisher, unfamiliar descriptions or names that mimic system files such as "svchost.exe" running from AppData. Note each process and its full path before terminating it.
Next, launch Autoruns as Administrator. Walk through the tabs systematically and uncheck entries that point to unfamiliar file locations, particularly anything under %AppData%, %LocalAppData% or %ProgramData%. Pay special attention to the scheduled tasks and services tabs, where the more resilient variants hide.
Run a full scan with the offline antivirus scanner, then a second scan with a different engine such as Malwarebytes or ESET. The two-engine approach catches samples that one vendor has not yet flagged. After scans, restart normally and repeat. If the trojan reappears, persistence is still active and you will need to inspect the Run keys and scheduled tasks again.
Finally, reset each affected browser. Remove suspicious extensions, clear the startup and search engine settings and verify the proxy settings have not been altered. Restart once more, then monitor network traffic for a full hour to confirm there is no rogue outbound connection.
Hardening the system afterwards
Cleanup is only half the battle. Patch the operating system, the browser and every plugin, as many codec trojans exploit outdated media frameworks such as Flash or legacy DirectShow filters. Enable reputation-based protection in Windows Security and switch on controlled folder access if your version of Windows supports it.
Review the habits that led to the infection. Avoid downloading codec packs from unfamiliar sources, since modern players such as VLC and MPC-HC already ship with most codecs built in. Stick to official mirrors for any software, and treat every unsolicited email attachment with caution, including those that appear to come from local institutions.
Schedule a quarterly review of installed programs and browser extensions. Australian households with multiple users, such as a family in Brisbane with shared computers, benefit from creating a standard user account for everyday activity and reserving the administrator account for installs. The combination of careful habits and a clean baseline keeps the trojan from coming back.