Saturday, July 19, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\xevhbpw.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{201a14d7-b5b4-422c-816f-5f2a1e92e0e7}"="incorrectnesses"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.