Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 23 March 2006 14:27:07 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zlob-GO is a downloader Trojan for the Windows platform.
Troj/Zlob-GO disquises itself as "eMedia Codec 4.0 Setup" and displays a license agreement. A folder may be created called <Program Files>\eMedia Code, containing the clean file uninst.exe, which will remove the folder but not the Trojan.
When installed Troj/Zlob-GO drops and runs the following files:
<System>\dfrgsrv.exe
<System>\<random>.tmp
Both files are also detected as Troj/Zlob-GO. The file <random>.tmp is injected into the process winlogon.exe.
The following registry entry is created to run dfrgsrv.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
wininet.dll
dfrgsrv.exe
Registry entries are created under:
HKCR\EMediaCodec.Chl\CLSID\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eMedia Codec\
