Thursday, November 13, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\wakjs.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{257f6f44-2c64-46bb-acb4-55f9b9e0ae08}"="flaxen"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.