Wednesday, May 7, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\rtmipr.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193}"="delayingly"

It also installs Toolbar, BHO, VirusHeat Rogue software...

SmitfraudFix removes the infection.