Wednesday, June 18, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\funfsnv.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{99f8405b-63d1-421a-83bb-7b4b0642ac28}"="eulogical"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.