Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 3 May 2005 12:49:44 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zlob-I is a Trojan that attempts to download further malicious code. Troj/Zlob-I is a Trojan that attempts to download further malicious code.
The Trojan attempts to set itself to run on system startup by creating the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
notepad.exe
msmsgs.exe
Troj/Zlob-I also adds MSMSGS.EXE to the following registry entry in order to run itself on system startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Troj/Zlob-I creates a registry entry at the following location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
uuid
Troj/Zlob-I attempts to stealth itself by injecting itself into EXPLORER.EXE or by registering itself as a service process.
Troj/Zlob-I may store downloaded files in the LogFiles subfolder of the Windows system folder.
