Home Malware Programs Trojans Zlob.Trojan

Zlob.Trojan

Posted: April 28, 2011

Threat Metric

Ranking: 5,470
Threat Level: 9/10
Infected PCs: 32,590
First Seen: July 24, 2009
Last Seen: March 8, 2025
OS(es) Affected: Windows

ScreenshotZlob.Trojan is a malicious and extremely dangerous Trojan horse program that installs itself secretly on your computer. Zlob.Trojan then opens up a backdoor security hole, allowing remote attackers to control your computer, execute programs, download additional malware, and steal personal data and credit card information. Zlob.Trojan may also install rogue anti-spyware programs and open excessive pop-up advertisements trying to get you to register them. Zlob is known to be affiliated with SysProtectionPage.com, Systemuptodate.com, Safetyuptodate.com, ULWindowSeek.com, ULWindowURL.com, SysUpdateCenter.com, SysNetSecurity.com, Securityuptodate.com, Guarduptodate.com, Necessaryupdates.com, dlpatch.com, and Vundo.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

TROJ_FAKEAL.SMAC [TrendMicro]Trojan.Win32.Bredolab.Gen.pac (v) [Sunbelt]Sus/UnkPack-C [Sophos]Gen:Variant.Renos.21 [BitDefender]Mal/Cognac-A [Sophos]TrojanDownloader:Win32/Renos.DZ [Microsoft]W32/Heuristic-USU!Eldorado [Authentium]BKDR_ULTIMATE.CJ [TrendMicro]a variant of Win32/Kryptik.AGY [NOD32]Artemis!135C4E5F27D7 [McAfee+Artemis]Backdoor.Win32.UltimateDefender.yt [F-Secure]Trojan.Generic.2333096 [BitDefender]Generic14.ALSK [AVG]Backdoor.Win32.UltimateDefender.yj [Kaspersky]Generic14.AEMV [AVG]
More aliases (3123)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Zlob.Trojan may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



msmsgs.exe File name: msmsgs.exe
Size: 5.48 KB (5481 bytes)
MD5: 91e2a8128cde75db5f1e8831a3cc615a
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2010
servicelayer.exe File name: servicelayer.exe
Size: 333.31 KB (333312 bytes)
MD5: 01fdcf859caa46f5053b696da98dfb2a
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
lsass.exe File name: lsass.exe
Size: 279.55 KB (279552 bytes)
MD5: 004227513146a752c1caa3297cc685e3
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
ctfmon.exe File name: ctfmon.exe
Size: 279.55 KB (279552 bytes)
MD5: f43499a2b85f62e322a393e8e8475c65
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
rxjddnvj.exe File name: rxjddnvj.exe
Size: 91.66 KB (91667 bytes)
MD5: e6a9d7e99c26d59a438432f5def9f75c
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2010
gtxiz.exe File name: gtxiz.exe
Size: 14.33 KB (14336 bytes)
MD5: 373437440d4794d7f595d12b3931b6bb
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
pg32.exe File name: pg32.exe
Size: 84.99 KB (84992 bytes)
MD5: 938e4635667ad33133f42221d0c347eb
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2010
alofkmn.dll File name: alofkmn.dll
Size: 200.7 KB (200704 bytes)
MD5: f1afe59d76b17ef04799f58b22d102e0
Detection count: 55
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
apdqnxp.dll File name: apdqnxp.dll
Size: 266.24 KB (266240 bytes)
MD5: 3e763ba9c1723f46ebf7548afe6a6d98
Detection count: 52
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
kgqfweltgbn.dll File name: kgqfweltgbn.dll
Size: 307.2 KB (307200 bytes)
MD5: 43c814a008c3df5526f5dc3f5f748bce
Detection count: 51
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
amoumain.exe File name: amoumain.exe
Size: 328.19 KB (328192 bytes)
MD5: 2d64d471b1b7be1d91d906ac0d198aae
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
awlpwn.exe File name: awlpwn.exe
Size: 157.18 KB (157184 bytes)
MD5: 06872765fe8301f2715c818d8c02fecf
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 29, 2010
394559.dll File name: 394559.dll
Size: 13.31 KB (13312 bytes)
MD5: 39e90955020d8f5f2fea404f657bbfeb
Detection count: 34
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
818646.dll File name: 818646.dll
Size: 13.82 KB (13824 bytes)
MD5: a86a439a52cfa27998c61f4a8af9cc51
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
286858.dll File name: 286858.dll
Size: 13.82 KB (13824 bytes)
MD5: 19fe7fcc23afa9ecaf1093d9f7241b1b
Detection count: 32
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
a.exe File name: a.exe
Size: 91.65 KB (91652 bytes)
MD5: faa384e360b87eb75c03c09df86a521d
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
382077.dll File name: 382077.dll
Size: 13.31 KB (13312 bytes)
MD5: c0c37dec2ef1f6f1cb775c450a807764
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
409271.dll File name: 409271.dll
Size: 13.31 KB (13312 bytes)
MD5: 4705e0b048cbf041516812a6a3966a5d
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
sysrest32.exe File name: sysrest32.exe
Size: 34.3 KB (34304 bytes)
MD5: 8076ca097c94e04e176c0819773a6386
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ecjew.exe File name: ecjew.exe
Size: 23.55 KB (23552 bytes)
MD5: 6649a292ee55554b0a408c075341a85f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2010
wmsdkns.exe File name: wmsdkns.exe
Size: 89.51 KB (89515 bytes)
MD5: f28877d7b6482e4446c94b6fb85eb42d
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2010
iftuyszv.exe File name: iftuyszv.exe
Size: 90.07 KB (90073 bytes)
MD5: 12957dcc23da07c47c742fbb2cb970ab
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2010
vbpdtvdp.exe File name: vbpdtvdp.exe
Size: 87.51 KB (87511 bytes)
MD5: 3d10711e60a12d49de7ea92169807e95
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2010

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0BD44AB1-76A7-4E05-92F4-4B065FE72BD6}{144A6B24-0EBC-4D89-BF09-A06A718E57B5}{15C7D7AD-A87A-4C0D-9D8B-637FCD3488EF}{1D1B2879-99FF-11E3-8D96-D7ACAC95952A}{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}{3F5A62E2-51F2-11D3-A075-CC7364CAE42A}{4D25F921-B9FE-4682-BF72-8AB8210D6D75}{51B15F5A-E98B-4658-B9CB-9307B74773A7}{56B38F40-4E70-11d4-A076-0080AD86BA2F}{7265100a-17e1-41bf-bd08-63b95a25a9c3}{9527D42F-D666-11D3-B8DD-00600838CD5F}{9C22FF6B-11B2-43B0-9F1A-8B0C209C1FAB}{A95B2816-1D7E-4561-A202-68C0DE02353A}{AA1F9DDB-E605-4ba6-81D4-E427DEE012AD}{BE1A344F-9FF5-4024-949B-52205E6DB2D0}{C14E6230-757D-4246-81CE-B34E2940C722}{CFEE97A3-4911-444D-8BE8-E243A23D3DE2}{DF4E7A0C-E233-4906-B4C1-A404356541FF}{fce1c203-ff2b-4ec1-9983-e2900d29bbd8}File name without pathcgmopenbho.dllLive Sex.lnkSearchSettings.dllwww.youporn.com.lnkRun keysmsiexec.exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IE Custom ToolsIE Safety FeaturesInformation CenterSafety Alerter 2006Video ActiveX ObjectWindows Safety Alert

Additional Information

The following directories were created:
%ProgramFiles%\LPVideoPlugin%ProgramFiles%\NetProject%ProgramFiles%\SiteEntry%ProgramFiles%\Video ActiveX Access%ProgramFiles%\Video ActiveX Object%ProgramFiles%\Video Add-on%ProgramFiles%\Web Technologies%ProgramFiles%\WebMediaViewer
The following cookies were detected:
asecuremaskbasic-codecemcodecgayfetishiesafetywarningmaletube4freemalwarealarmmovieportal2008amoviesportal2008yyyprotectstandsafetyonlinepagethemymoviessitethesafetyfilesvcodec
The following URL's were detected:
2009dr.com592dr.cn9cdn.comcaoqn888.cnlaoqn.comnetcdn.com
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.