Friday, October 10, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\obicx.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{fb357e54-83f1-4a3c-80a2-319201ed6c17}"="bisque"

It also installs Toolbar, BHO, Virus Response Lab 2009 software...

SmitfraudFix removes the infection.