Thursday, August 21, 2008

Zlob

Zlob fake codec has been update. It drops the following file:

%SYSTEM%\kcekz.dll

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8dc71747-ace0-40c1-8947-54f107d0639b}"="enorganic"

It also installs Toolbar, BHO, Antispycheck Rogue software...

SmitfraudFix removes the infection.