Sophos

Troj/Zlob-CK

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 10 January 2006 06:03:25 (GMT)
Last updated 3 April 2006 14:54:35 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Zlob-CK is a Trojan for the Windows platform.

The Trojan contains functionality to access the Internet, download files and set registry entries.

When Troj/Zlob-CK is installed it creates the file <System>\netwrap.dll.

The following registry entry is created to run code exported by NetWrap for Windows on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ SharedTaskScheduler
{C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D}
NetWrap for Windows

The following registry entry is set:

HKCU\Software\Classes\CLSID\{C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D}\InProcServer32
(default)
<System>\netwrap.dll

Registry entries are created under:

HKCU\Software\Classes\CLSID\{C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D}\InProcServer32\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer