Home / Spyware Encyclopedia / Trojan.Zlob
 Trojan.Zlob Technical Details
Category Trojan
Discovered 7/22/2005 12:00:00 AM
Modified 12/12/2009 3:32:32 PM
Threat Level Critical
Category Description

A destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves but they can be just as destructive. One of the most insidious types of Trojan horse is a program that claims to rid your computer of viruses but instead introduces viruses onto your computer.
Notice
Summary

The following http urls were started:
•spywareisolator.com/setup_en.exe
•spywareiso.com/setup_en.exe
•spywareisolator2008.com/setup_en.exe
The hosts file was updated with the following url-to-ip mappings:
217.20.175.74 scan.vavscan.com
217.20.175.74 scanner.vavscan.com
217.20.175.74 vav2008.com
The following internet connection was established:
142.165.39.16 : 3531
71.199.180.68 : 3531
71.194.186.87 : 3531

The following Files were created:

NameVersionPublisherSignature (MD5)File Size (in KB)
..\meandyou.exe5.0.2169.1ZLAXAE Corporation8532ab9d5b20fb2f16a4948fd84782c2393216
..\you.exe5.0.2169.1ZDAVJU Corporation35b48da0e6ccfe75443f5f727a8f400a399872
..\686B8941.EXE5.0.2169.1ZDACAO Corporationf577f8e3cadf5ee66955c576a34b69c124064
..\SeekmoSA.exe10.0.431.0Zango, Inc.f79ac2af64dfddf2ceccf3b49be4262d796424
..\SeekmoSADF.exe10.0.431.0Zango, Inc.c22c3bbfe17c947aa7686c358faaa72c152840
..\SeekmoUnInstaller.exe10.0.431.0Zango, Inc.3561cffc54682a344c816d95fc507e38312576
..\SeekmoSA.exe10.0.431.0Zango, Inc. 796424
..\SeekmoSADF.exe10.0.431.0Zango, Inc. 152840
..\SeekmoUnInstaller.exe10.0.431.0Zango, Inc. 312576
..\plugins\npclntax_SeekmoSA.dll10.0.431.0Zango, Inc.9471eafbb8759bf20f8527ec6c1392d169896
..\CoreSrv.dll10.0.0.0Zango, Inc.  
..\SeekmoSAHook.dll10.0.431.0Zango, Inc.  
..\plugins\npclntax_SeekmoSA.dll10.0.431.0Zango, Inc. 69896
..\SeekmoSAAX.dll10.0.431.0Zango6b76997e2248776f5d2326446c102f1f2389256
..\B94D0374.EXE1.0.0.0Yahoo!9d5011e9aa8ec4960ea7a4d5e2b8bf2b151552
..\F3492DA5.EXE1.0.0.0yaghoob.ekrami@yahoo.com91ba87616839bdf9af7b0e1df0316c5d364544
..\01F19FC3.EXE1.0.0.0yaghoob.ekrami@yahoo.com649209ee1d4bacfc5c36ec4975677ee6462848
..\20E538C1.EXE4.6.6.4Yd6d746d71f94faaba35222168c25b9f0282624
..\XPPoliceAntivirus\AVCoreFn.dll1.0.0.1xxx Softwareec26f2b86f4841b54a8ce6af5f817231577536
..\113EC952.EXE1.0.0.0Xvisionf720894dff55b978d7384dd9b08c7fd520480
..\B064CEF0.EXE1.0.0.0xTr Software957c07534ef71d3f913ff8a4b37f27d436864
..\E642510D.EXE5.0.2169.1XRABJE Corporation65c859697ae1b1d4d848cf13065eb3df24064
..\ld46.exe5.0.2169.1XKACAJ Corporation0a5d98e552b182fb7b56e91e109befc656320
..\youandme.exe5.0.2169.1XGACAJ Corporation35b48da0e6ccfe75443f5f727a8f400a393216
..\BE6B9D22.EXE1.0.0.0x580469bb95f5d39f11c0e13e9f8e7b6827682
..\2DBBEB46.EXE1.0.0.0xb3b263c5e6f4fbd908643dfc57e9e38c20480
..\UUSEE\IN_NET.DLL1.0.8.504WWW.UUSEE.COMf96098cfa8a83c697d2a18d68fb8fbb3925000

The following Registry Entries were created:

..\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\"{89fdcc4b-8d91-49b0-81a6-18bcff582735}"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"09375087131971375270878830669170"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"systemdriver"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"salestart"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"39247163632169364003994714568076"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"bmn(1)"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"tpxhst32.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"ohccuxdg"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"itzeyqjm"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"uoeinagp"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"fixwiadl"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"mrupmrof"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"upcreten"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"adriver"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"wblogon"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"sbkrwpsh"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"fgrsxszq"

Recommendation to remove Trojan.Zlob

Spyware Detector can remove Trojan.Zlob, and thousands of other Spyware automatically and instantly. Click here to download Spyware Detector and scan for free.
Download Spyware Detector and Scan for FREE
 
Search Threats
Customer Service Rating by LivePerson