Home / malwarePDF  

Zlob


First posted on 01 March 2007.
Source: SecurityHome

Aliases :

Zlob is also known as W32/Zlob, Trojan-Downloader.Win32.Zlob, Win32.Trojandownloader.Zlob.

Explanation :

Zlob is a Trojan. Zlob attempts to hiddenly download and run other files from remote web sites and shows fake error messages. Zlob copies itself to the Windows folder and changes startup and search pages of Internet Explorer.

Zlob downloads and installs Spyware and Adware applications. Most of them are considered to be rogue anti-spyware:



Some of the recent versions include a backdoor component which allow the attacker to manipulate the victim's PC. Zlob itself is installed on the system by tricking the user into downloading a fake codec or protection system, such as:


Note: Most of the names above are also .com domains as well, e.g. VidCodecs.com.


The installation process creates some of these files (depends on the variant).



Depending on the variant of Zlob, %DESTDIR% represents:



Creates registry run keys and Class IDs in:

Last update 01 March 2007

 

TOP

Malware :

Family: