Friday, November 28, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\ftfea.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{22ef8ba1-a18c-4ad3-ad84-01b95b581c5c}"="fractabling"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.