CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Zlob Trojan

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
spywarebox

MIRT Hunter


Joined: Apr 21, 2007
Posts: 68
Location: CANADA
MIRT

PostPosted: Mon Feb 25, 2008 8:13 pm    Post subject: Zlob Trojan
Reply with quote

hxxp://www.viewdevice.com/download.php?id=1515

Back to top
View users profile Send private message MSN Messenger
maliciousbrains

Sergeant
Sergeant
Premium Member

Joined: Feb 23, 2008
Posts: 103

Premium

PostPosted: Mon Feb 25, 2008 8:25 pm    Post subject: Trojan.Zlob: Level 1 Threat
Reply with quote

Trojan.Zlob is a back door Trojan that allows the remote attacker to perform various malicious actions on the compromised computer.

When Trojan.Zlob is executed, it performs the following actions:

Copies itself as one of the following files:


%System%\msmsgs.exe
%System%\ld100.tmp
%System%\regperf.exe

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the following value:

"Shell" = "Explorer.exe, msmsgs.exe"

to the registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

so that the Trojan runs every time Windows starts.


Creates the following value:

"MSN Messenger" = "%System%\msmsgs.exe"

to the registry subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs every time Windows starts.


Adds the following value:

"uuid" = "86c29b2f-3389-418b-9b47-c2b09b6abc07"

to the registry subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion


Adds one of the following values:

"wininet.dll" = "regperf.exe"
"notepad.exe" = "msmsgs.exe"

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

so that the Trojan runs when Windows starts or the user logs on.


Injects itself into the explorer.exe process.


Attempts to make HTTP connections to the following domains using different URLs, which allow the Trojan to ping, report it's status, and execute remote files:


vnp7s.net
zxserv0.com
dumpserv.com

Removal:
Run a full system scan.
If any files are detected as infected with Trojan.Zlob, click Delete.

Warning messages may be displayed when the computer is restarted, as the threat has not been fully removed at this point. Please ignore these messages and just click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [File path]
Message body: Windows cannot find [file name]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

To delete the value from the registry

Make a backup of the registry then follow the steps:

Click Start > Run.
Type regedit
Click OK.


Navigate to the following subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon


In the right pane, delete the value:

"Shell" = "Explorer.exe, msmsgs.exe"


Navigate to the following subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"MSN Messenger" = "%System%\msmsgs.exe"


Navigate to the following subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion


In the right pane, delete the value:

"uuid" = "[random characters]"


Navigate to the following subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\explorer\Run


In the right pane, delete the value:

"notepad.exe" = "msmsgs.exe"


Exit the Registry Editor.


.:: Malicious Brains ::.
http://maliciousbrains.blogspot.com/

Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Tue Feb 26, 2008 3:06 am    Post subject:
Reply with quote

Most AV companies can detect this malware.

http://www.siteadvisor.com/sites/viewdevice.com/


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer