Monday, November 24, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\eebpj.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{854b8525-c907-4258-bc2e-7b118037419c}"="disaffiliation"

It also installs Toolbar, BHO, VirusTrigger software...

SmitfraudFix removes the infection.