Sophos

Troj/Zlob-KV

Aliases
  • Trojan-Downloader.Win32.Zlob.py
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Detected by All Sophos products

Action

More Information

Troj/Zlob-KV is a downloader and browser-hijacking Trojan for the Windows platform.

When first run, Troj/Zlob-KV copies itself to the following location :

<System>\regperf.exe

Troj/Zlob-KV also creates the following file :

<System>\l<random>.tmp

where <random> is a randomly chosen number. This file is also detected as Troj/Zlob-KV.

The following registry entry is created to run regperf.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
wininet.dll
regperf.exe

Troj/Zlob-KV will inject code into the winlogon.exe process and can thus remain resident and execute its malicious functionality under this guise.

Troj/Zlob-KV may attempt to download and execute code from a remote website, and may also attempt to modify Internet Explorer settings such as the browser homepage by modifying the following registry value :

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main
Start Page

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer