Sunday, November 30, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\cwegus.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{4d5b7736-a3bc-4e5b-9fa2-1bcc3e587abb}"="evacuative"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.