Monday, July 28, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\yizgdux.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ba934431-76af-4c99-93c2-c3d21944a72e}"="chokestrap"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.