Thursday, August 28, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\wighg.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{cac60ee7-ebe0-4082-be2a-3abf704b7af0}"="glycosulfatase"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.