Antivirus and Security Software from Sophos

Sophos blogs

Troj/Zlob-KB

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 25 May 2006 22:27:50 (GMT)
Last updated 26 June 2006 21:10:03 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Zlob-KB is a Trojan for the Windows platform.

When Troj/Zlob-KB is installed the following files are created:

<Windows system folder>\simpole.tlb
<Windows system folder>\stdole3.tlb
<Windows system folder>\hp<rnd>.tmp

where <rnd> is a random string of characters.

The files hp24B9.tmp and simpole.tlb are detected as Troj/Zlob-KB.

The file hp24B9.tmp is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f79fd28e-36ee-4989-aa61-9dd8e30a82fa}
HKCR\CLSID\{F79FD28E-36EE-4989-AA61-9DD8E30A82FA}

Troj/Zlob-KB changes Start Page and search settings for Microsoft Internet Explorer by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Search\
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer