Sunday, December 21, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\ijofmsu.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2ecca339-c274-40e3-a582-ef4c0e917639}"="bussebuschke"

It also installs Toolbar, BHO, Antivirus Trigger software...

SmitfraudFix removes the infection.