Sophos

Troj/Zlob-XU

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 4 January 2007 21:00:28 (GMT)
Last updated 11 January 2007 02:05:41 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Zlob-XU is a Trojan for the Windows platform.

Troj/Zlob-XU pretends to be an installer called "DirectVideo Setup".

When Troj/Zlob-XU is installed it creates the file <System>\kdcmt.exe. This file is also detected as Troj/Zlob-XU and contains stealthing functionality.

Troj/Zlob-XU also drops a file detected as Troj/DNSChan-JS.

The following registry entry is changed to run kdcmt.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
kdcmt.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer