Global Information Lookup Global Information

Zlob trojan information


Common nameZlob
Technical name
  • TrojanDownloader:Win32/Zlob (Microsoft)
  • Trojan.Zlob (Symantec)
  • Trojan.Zlob.[Letter] (Symantec)
  • Trojan-Downloader:W32/Zlob (F-Secure)
  • Win32.Trojandownloader.Zlob (F-Secure)
  • Trojan-Downloader.Win32.Zlob (F-Secure)
  • TROJ_ZLOB.[Letter] (Trend Micro)
  • Trojan-Downloader.Win32.Zlob.[letter] (Kaspersky)
  • Downloader.Win32.Zlob.[Letter] (Kaspersky)
  • TR/Dldr.Zlob.Gen (Avira)
  • TR/Drop.Zlob.[Letter] (Avira)
TypeMalware
SubtypeSpyware

The Zlob Trojan, identified by some antiviruses as Trojan.Zlob, is a Trojan horse which masquerades as a required video codec in the form of ActiveX. It was first detected in late 2005, but only started gaining attention in mid-2006.[1]

Once installed, it displays popup ads which appear similar to real Microsoft Windows warning popups, informing the user that their computer is infected with spyware. Clicking these popups triggers the download of a fake anti-spyware program (such as Virus Heat and MS Antivirus (Antivirus 2009)) in which the Trojan horse is hidden.[1]

The Trojan has also been linked to downloading atnvrsinstall.exe which uses the Windows Security shield icon to look as if it is an anti-virus installation file from Microsoft. Having this file run can wreak havoc on computers and networks. One typical symptom is random computer shutdowns or reboots with random comments.[further explanation needed] This is caused by the programs using Task Scheduler to run a file called "zlberfker.exe."

Project Honeypot Spam Domains List (PHSDL)[2] tracks and catalogs spam domains. Some of the domains on the list are redirects to porn sites and various video watching sites that show a number of online videos. Playing videos on these sites activates a request to download an ActiveX codec which is malware. It prevents the user from closing the browser in the usual manner. Other variants of Zlob Trojan installation come in the form of a Java cab file masquerading as a computer scan.[3]

There is evidence that the Zlob Trojan might be a tool of the Russian Business Network[4] or at least of Russian origin.[5]

  1. ^ a b "The ZLOB Show: Trojan Poses as Fake Video Codec, Loads More Threats". Trend Micro. Retrieved 26 November 2007.
  2. ^ Project Honeypot Spam Domains List
  3. ^ PHSDL Zlob Trojan Forum Spam Hijacking Attempt Documentation
  4. ^ "RBN – Fake Codecs".
  5. ^ "TCP – Проект Киберкультуры | Zlob Team".

and 6 Related for: Zlob trojan information

Request time (Page generated in 0.7535 seconds.)

Zlob trojan

Last Update:

The Zlob Trojan, identified by some antiviruses as Trojan.Zlob, is a Trojan horse which masquerades as a required video codec in the form of ActiveX....

Word Count : 762

Timeline of computer viruses and worms

Last Update:

susceptible to infection by worms and viruses. Late 2005: The Zlob Trojan, is a Trojan horse program that masquerades as a required video codec in the...

Word Count : 7663

Browser hijacking

Last Update:

browsers. Search-daily.com is a hijacker that may be downloaded by the Zlob trojan. It redirects the user's searches to pornography sites. It is also known...

Word Count : 2428

RSPlug

Last Update:

the DNS-changing Mac Trojan is the same group behind the Zlob trojan. However, Intego noted that those behind the RSPlug Trojan horse stopped their activities...

Word Count : 310

Emcodec

Last Update:

user's browsing and acts as adware. Some versions of the trojan install malware called Zlob, which in turn may lead to the installation of malicious and...

Word Count : 285

Forum spam

Last Update:

attempts to close the Website an ActiveX codec will be downloaded as a Zlob Trojan. The spambot can often bypass many of the safeguards administrators use...

Word Count : 1032

PDF Search Engine © AllGlobal.net