Friday, June 13, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\kfcpnd.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{5c7b71bb-6d49-4bdc-b60d-f9fe0481eb5f}"="campaniform"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.