Zlob trojan Information & Zlob trojan Links at HealthHaven.com
advertise
add site
services
publishers
database
health videos
Bookmark and Share

search wiki for    ?
web dir firms image gallery news pdf wiki shop video 
about
toolbar
stats
live show
health store
more stuff
JOIN/LOGIN
Featured Results:
Newsletter: L-arginine, the Trojan Horse...
Newsletter: L-arginine, the Trojan Horse...
enews.endocrinemetabolic....
 Cancer Forums - Cancer News - Trojan Horse
Cancer Forums - Cancer News - Trojan Horse
cancerforums.net
 METHANOL: A CHEMICAL TROJAN HORSE AS THE ROOT OF THE INSCRUTABLE U.
METHANOL: A CHEMICAL TROJAN HORSE AS THE ROOT OF THE INSCRUTABLE U.
wnho.net
 BIG PHARMA TROJAN HORSES PERMEATE SUPPLEMENT INDUSTRY - La Leva di...
BIG PHARMA TROJAN HORSES PERMEATE SUPPLEMENT INDUSTRY - La Leva di...
laleva.org
 

The Zlob Trojan, also known as Trojan.Zlob, is a trojan horse which masquerades as a needed video codec in the form of ActiveX. It was first detected in late 2005, but only started gaining attention in mid-2006.[1] Once installed, it displays popup ads with appearance similar to real Microsoft Windows warning popups, informing the user that their computer is infected with spyware. Clicking these popups triggers the download of a fake anti-spyware program (such as Virus Heat and MS Antivirus (Antivirus 2009)) in which the trojan horse is hidden.[1]

The group that created Zlob have also created a Mac trojan with similar behaviours (named RSPlug).[2] Some variants of the Zlob family, like the so-called DNSChanger, add rogue DNS name servers to the Registry of Windows-based computers[3] and attempt to hack into any detected router to change the DNS settings and therefore could potentially re-route traffic from legitimate web sites to other suspicious web sites.

The trojan has also been linked to downloading atnvrsinstall.exe which uses the Windows Security shield icon to look as if it is an Anti Virus installation file from Microsoft. Having this file initiated can wreak havoc on computers and networks. One symptom is random computer shutdowns or reboots with random comments. This is caused by the programs using Scheduled Tasks to run a file called "zlberfker.exe".

PHSDL - Project Honeypot Spam Domains List[4] tracks and catalogues Zlob spam Domains. Some of the domains on the list are redirects to porn sites and various video watching sites that show a number of inline videos. Clicking on the video to play activates a request to download an ActiveX codec which is malware. It prevents the user from closing the browser in the usual manner. Other variants of Zlob Trojan installation are in the form of computer scan that comes as a Java cab.[5]

There is evidence that the Zlob trojan might be a tool of the Russian Business Network[6] or at least of Russian origin.[7]

[edit] References

[edit] External links

Anti Zlob Malware Forums




Product Results (view all...)

search wiki for    ?
web dir firms image gallery news pdf wiki shop video 



↑ top of page ↑about thumbshots