Sophos

Troj/Zlob-K

Aliases
  • Trojan-Downloader.Win32.Zlob.s
  • Downloader-XC
  • Trojan.Zlob.B
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 28 June 2005 05:21:52 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Zlob-K is a downloader Trojan.

Troj/Zlob-K will contact predefined remote sites and download data. The Trojan may then download further executable files and run them. Troj/Zlob-K is a downloader Trojan.

Troj/Zlob-K will contact predefined remote sites and download data. The Trojan may then download further executable files and run them.

In order to run automatically each time Explorer initializes, Troj/Zlob-K will
set the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
notepad.exe
msmsgs.exe

In order to run automatically each time a user logs in, Troj/Zlob-K will add MSMSGS.EXE to the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell

Troj/Zlob-K will attempt to hide its activity by injecting code into
EXPLORER.EXE.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer