Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 29 January 2008 20:14:28 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zlob-AHZ is a Trojan for the Windows platform.
When Troj/Zlob-AHZ is installed the following files are created:
<Windows>\adsoowf.dll
<Windows>\bgrlsmn.dll
<Windows>\dat.txt
<Windows>\dntpkwoxsp.dll
<Windows>\ekxdvft.dll
<Windows>\ffvrdgt.exe
<Windows>\rs.txt
<Windows>\search_res.txt
the text files are data files and the rest of the files are detected as Troj/Zlob-AHZ
The files adsoowf.dll, bgrlsmn.dll and dntpkwoxsp.dll are registered as COM objects, creating registry entries under:
HKCR\CLSID\{04E9C24C-CB18-4FEA-8DE1-E6984E68A4F9}
HKCR\CLSID\{12100F01-47C9-470E-90A9-01064559B0A9}
HKCR\CLSID\{236140D2-2846-4D32-9A0B-5365F850B3D3}
HKCR\CLSID\{55A0DF3F-A2D1-449C-9726-D8B9BCB6F08C}
HKCR\CLSID\{59034300-E6C2-4DD0-92CF-0D86D470B87C}
HKCR\CLSID\{6BCCC33D-0E20-4656-8FEF-47BD620A98FE}
HKCR\CLSID\{8AD01104-3996-4F85-B01F-A13A5BA56770}
HKCR\Interface\{165525D4-5BED-4A4E-98DB-D4DDB3DAD7DD}
HKCR\Interface\{6ADA34E7-8ACE-47D2-BA52-42890E8C1980}
HKCR\TypeLib\{E3FA4F31-D584-486C-8C5B-4DD074413461}
The file dntpkwoxsp.dll is registered as a Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{236140D2-2846-4D32-9A0B-5365F850B3D3}
The following registry entries are created to run code exported by adsoowf.dll and bgrlsmn.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
bgrlsmn
{6BCCC33D-0E20-4656-8FEF-47BD620A98FE}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
adsoowf
{04E9C24C-CB18-4FEA-8DE1-E6984E68A4F9}
The following registry entry is set:
HKCR\MSVPS.MSVPSApp\CLSID
(default)
{236140D2-2846-4D32-9A0B-5365F850B3D3}
Registry entries are created under:
HKCR\MSVPS.MSVPSApp
HKLM\SOFTWARE\Microsoft\VideoPlugin
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
Troj/Zlob-AHZ claims to provide an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "WebVideo Support".
