Home Malware Programs Trojans Zlob.Trojan

Zlob.Trojan

Posted: April 28, 2011

Threat Metric

Ranking: 3,065
Threat Level: 9/10
Infected PCs: 31,785
First Seen: July 24, 2009
Last Seen: October 16, 2023
OS(es) Affected: Windows

ScreenshotZlob.Trojan is a malicious and extremely dangerous Trojan horse program that installs itself secretly on your computer. Zlob.Trojan then opens up a backdoor security hole, allowing remote attackers to control your computer, execute programs, download additional malware, and steal personal data and credit card information. Zlob.Trojan may also install rogue anti-spyware programs and open excessive pop-up advertisements trying to get you to register them. Zlob is known to be affiliated with SysProtectionPage.com, Systemuptodate.com, Safetyuptodate.com, ULWindowSeek.com, ULWindowURL.com, SysUpdateCenter.com, SysNetSecurity.com, Securityuptodate.com, Guarduptodate.com, Necessaryupdates.com, dlpatch.com, and Vundo.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

TROJ_FAKEAL.SMAC [TrendMicro]Trojan.Win32.Bredolab.Gen.pac (v) [Sunbelt]Sus/UnkPack-C [Sophos]Gen:Variant.Renos.21 [BitDefender]Mal/Cognac-A [Sophos]TrojanDownloader:Win32/Renos.DZ [Microsoft]W32/Heuristic-USU!Eldorado [Authentium]BKDR_ULTIMATE.CJ [TrendMicro]a variant of Win32/Kryptik.AGY [NOD32]Artemis!135C4E5F27D7 [McAfee+Artemis]Backdoor.Win32.UltimateDefender.yt [F-Secure]Trojan.Generic.2333096 [BitDefender]Generic14.ALSK [AVG]Backdoor.Win32.UltimateDefender.yj [Kaspersky]Generic14.AEMV [AVG]
More aliases (3123)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



msmsgs.exe File name: msmsgs.exe
Size: 5.48 KB (5481 bytes)
MD5: 91e2a8128cde75db5f1e8831a3cc615a
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2010
servicelayer.exe File name: servicelayer.exe
Size: 333.31 KB (333312 bytes)
MD5: 01fdcf859caa46f5053b696da98dfb2a
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 279.55 KB (279552 bytes)
MD5: 004227513146a752c1caa3297cc685e3
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 359.93 KB (359936 bytes)
MD5: b422b8649f2e43f2bad1cab1effafd04
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 23, 2010
ctfmon.exe File name: ctfmon.exe
Size: 279.55 KB (279552 bytes)
MD5: f43499a2b85f62e322a393e8e8475c65
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 279.04 KB (279040 bytes)
MD5: 96c6e15d0b428c57e29a64a6c207955e
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 23, 2010
ctfmon.exe File name: ctfmon.exe
Size: 279.55 KB (279552 bytes)
MD5: 94a9d4ddaa7269f3d8804fc54abc0442
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 00c2d08728d7d798e33905e481d020d1
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 3622ae7e6f2e15f3e7f1d7415c1a6dac
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 279.55 KB (279552 bytes)
MD5: 135c4e5f27d7b580398f2af922e69eaf
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 281.6 KB (281600 bytes)
MD5: ce8e74c74f9d973553204eb3ad995bcd
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 281.6 KB (281600 bytes)
MD5: 8e7fd209e6c9878e62ce864d303b8fc9
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 281.6 KB (281600 bytes)
MD5: 0ea7c43d36d013c5a768941f7f6787a6
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: eac6e2e794b336957e7ac64c3fa75272
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 282.62 KB (282624 bytes)
MD5: 33d0ddceddf327a069bbdc607a408c14
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 281.6 KB (281600 bytes)
MD5: e15475172b6b3c60b1fac0a529f9ca19
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 033782d69a3e32e6c7f2d98a1e873649
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 664fae444e49262f0f251ea95aaceeeb
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 08c9a700425e7edc03b1487acf78c839
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: 444815d0a94b6abc741655a771c3ec96
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
lsass.exe File name: lsass.exe
Size: 280.57 KB (280576 bytes)
MD5: dd60d0fb5edc14b59ea5bef6b063c02d
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
servicelayer.exe File name: servicelayer.exe
Size: 320.51 KB (320512 bytes)
MD5: 06bb1e5d763010086cc13bfe210f766d
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
amoumain.exe File name: amoumain.exe
Size: 328.19 KB (328192 bytes)
MD5: 2d64d471b1b7be1d91d906ac0d198aae
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
ctfmon.exe File name: ctfmon.exe
Size: 337.92 KB (337920 bytes)
MD5: 7687ba9ce2cf5ded4831d98f4551faba
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
awlpwn.exe File name: awlpwn.exe
Size: 157.18 KB (157184 bytes)
MD5: 06872765fe8301f2715c818d8c02fecf
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 29, 2010

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0BD44AB1-76A7-4E05-92F4-4B065FE72BD6}{144A6B24-0EBC-4D89-BF09-A06A718E57B5}{15C7D7AD-A87A-4C0D-9D8B-637FCD3488EF}{1D1B2879-99FF-11E3-8D96-D7ACAC95952A}{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}{3F5A62E2-51F2-11D3-A075-CC7364CAE42A}{4D25F921-B9FE-4682-BF72-8AB8210D6D75}{51B15F5A-E98B-4658-B9CB-9307B74773A7}{56B38F40-4E70-11d4-A076-0080AD86BA2F}{7265100a-17e1-41bf-bd08-63b95a25a9c3}{9527D42F-D666-11D3-B8DD-00600838CD5F}{9C22FF6B-11B2-43B0-9F1A-8B0C209C1FAB}{A95B2816-1D7E-4561-A202-68C0DE02353A}{AA1F9DDB-E605-4ba6-81D4-E427DEE012AD}{BE1A344F-9FF5-4024-949B-52205E6DB2D0}{C14E6230-757D-4246-81CE-B34E2940C722}{CFEE97A3-4911-444D-8BE8-E243A23D3DE2}{DF4E7A0C-E233-4906-B4C1-A404356541FF}{fce1c203-ff2b-4ec1-9983-e2900d29bbd8}File name without pathcgmopenbho.dllLive Sex.lnkSearchSettings.dllwww.youporn.com.lnkRun keysmsiexec.exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IE Custom ToolsIE Safety FeaturesInformation CenterSafety Alerter 2006Video ActiveX ObjectWindows Safety Alert

Additional Information

The following directories were created:
%ProgramFiles%\LPVideoPlugin%ProgramFiles%\NetProject%ProgramFiles%\SiteEntry%ProgramFiles%\Video ActiveX Access%ProgramFiles%\Video ActiveX Object%ProgramFiles%\Video Add-on%ProgramFiles%\Web Technologies%ProgramFiles%\WebMediaViewer
The following cookies were detected:
asecuremaskbasic-codecemcodecgayfetishiesafetywarningmaletube4freemalwarealarmmovieportal2008amoviesportal2008yyyprotectstandsafetyonlinepagethemymoviessitethesafetyfilesvcodec
The following URL's were detected:
2009dr.com592dr.cn9cdn.comcaoqn888.cnlaoqn.comnetcdn.com
Loading...