Friday, April 25, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\zfaiqwr.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b0fdc513-46b9-46fc-8e70-d575ee546dae}"="frowardness "

It also installs Toolbar, BHO, VirusHeat Rogue software...

Use SmitfraudFix to remove the infection.