Sophos

Troj/Zlob-O

Aliases
  • Trojan-Downloader.Win32.Zlob.bl
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 3 December 2005 22:34:45 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Zlob-O is a downloader Trojan.

Troj/Zlob-O will contact predefined remote sites and download data. The Trojan may then download further executable files and run them. Troj/Zlob-O is a downloader Trojan.

Troj/Zlob-O will contact predefined remote sites and download data. The Trojan may then download further executable files and run them.

In order to run automatically each time Explorer initializes, Troj/Zlob-O will set the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
wininet.dll
mscornet.exe

Troj/Zlob-O will drop a component to the Windows system folder as ld<random>.tmp. This file is also detected as Troj/Zlob-O

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer