Thursday, November 20, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\tiltmeo.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e0feeb92-908e-46d2-8a66-88c5295f2629}"="crimsonness"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.