Tuesday, December 2, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\pbhha.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{51e7273d-911a-445a-bf46-bd4b86b0e87b}"="fddi"

It also installs Toolbar, BHO, AntivirusTrigger software...

SmitfraudFix removes the infection.