Sophos

Troj/Zlob-AHZ

Aliases
  • Adware:Win32/SmitFraud
  • TR/Dldr.Zlob.Gen
  • ADSPY/Agent.PB
  • Trojan:Win32/Zlob.B
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 29 January 2008 20:14:28 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Zlob-AHZ is a Trojan for the Windows platform.

When Troj/Zlob-AHZ is installed the following files are created:

<Windows>\adsoowf.dll
<Windows>\bgrlsmn.dll
<Windows>\dat.txt
<Windows>\dntpkwoxsp.dll
<Windows>\ekxdvft.dll
<Windows>\ffvrdgt.exe
<Windows>\rs.txt
<Windows>\search_res.txt

the text files are data files and the rest of the files are detected as Troj/Zlob-AHZ

The files adsoowf.dll, bgrlsmn.dll and dntpkwoxsp.dll are registered as COM objects, creating registry entries under:

HKCR\CLSID\{04E9C24C-CB18-4FEA-8DE1-E6984E68A4F9}
HKCR\CLSID\{12100F01-47C9-470E-90A9-01064559B0A9}
HKCR\CLSID\{236140D2-2846-4D32-9A0B-5365F850B3D3}
HKCR\CLSID\{55A0DF3F-A2D1-449C-9726-D8B9BCB6F08C}
HKCR\CLSID\{59034300-E6C2-4DD0-92CF-0D86D470B87C}
HKCR\CLSID\{6BCCC33D-0E20-4656-8FEF-47BD620A98FE}
HKCR\CLSID\{8AD01104-3996-4F85-B01F-A13A5BA56770}
HKCR\Interface\{165525D4-5BED-4A4E-98DB-D4DDB3DAD7DD}
HKCR\Interface\{6ADA34E7-8ACE-47D2-BA52-42890E8C1980}
HKCR\TypeLib\{E3FA4F31-D584-486C-8C5B-4DD074413461}

The file dntpkwoxsp.dll is registered as a Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{236140D2-2846-4D32-9A0B-5365F850B3D3}

The following registry entries are created to run code exported by adsoowf.dll and bgrlsmn.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
bgrlsmn
{6BCCC33D-0E20-4656-8FEF-47BD620A98FE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
adsoowf
{04E9C24C-CB18-4FEA-8DE1-E6984E68A4F9}

The following registry entry is set:

HKCR\MSVPS.MSVPSApp\CLSID
(default)
{236140D2-2846-4D32-9A0B-5365F850B3D3}

Registry entries are created under:

HKCR\MSVPS.MSVPSApp
HKLM\SOFTWARE\Microsoft\VideoPlugin
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo

Troj/Zlob-AHZ claims to provide an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "WebVideo Support".

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer