Zlob Trojan

Zlob malware description and removal detail
Categories:Trojan,Hijacker,Downloader,Popups
Also known as:

[Kaspersky]Trojan-Dropper.Win32.Agent.mu,Trojan-Downloader.Win32.Zlob.bnw,Trojan.Downloader.Win32.Zlob.azc,Trojan-Downloader.Win32.Agent.bbr,Trojan.Win32.Crypt.g,Trojan-Downloader.Win32.Zlob.bcl,Trojan-Downloader.Win32.Zlob.dah,Trojan.Win32.DNSChanger.pi,Adware.Win32.Agent.pz,Trojan-Downloader.Win32.Zlob.bxr,Trojan-Downloader.Win32.Zlob.ehi,Trojan-Downloader.Win32.Zlob.ehw,Trojan-Downloader.Win32.Zlob.enq,Trojan-Downloader.Win32.Obfuscated.bn;
[McAfee]Puper.gen,Generic Downloader,DNSChanger.pi;
[F-Prot]W32/Downloader.BECM;
[Panda]Adware/VideoAddon;
[Other]W32/Zlob.gen4,W32/Renos.gen3,TROJ_ZLOB.BQZ,Zlob.IOD,Trojan-Downloader.Zlob.Media-Codec,Trojan.Zlob.AVP,W32/DLoader.BCQL,Trojan.DownLoader.10588,W32/Zlob.gen70,Trojan.Zlob,Zlob.AGUA,Troj/Zlob-Gen,trojan-downloader-zlob,TROJ_ZLOB.DSI,Trojan-Downloader.Zlob.MediaCodec,W32/Zlob.AIRZ,W32/Zlob.ACPA,Troj/Agent-EOH,Downloader,Troj/Zlob-VH,Trojan-Downloader.Zlob.Media-COdec,Trojan.Emcodec,W32/Zlob.XJU,TrojanDownloader:Win32/Zlob.gen!N,TROJ_ZLOB.DYP,Mal/ZlobInst-A,TrojanDownloader:Win32/Zlob.gen!AA,Zlob.gen94,TrojanDownloader:Win32/Zlob.gen!R,Trojan:Win32/Zlob.ZWC,Troj/Zlobar-Fam

Visible Symptoms:
Files in system folders:
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ot.ico
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ts.ico
[%DESKTOP%]\Viruz\temp.fr????\ot.ico
[%DESKTOP%]\Viruz\temp.fr????\ts.ico
[%PROFILE_TEMP%]\temp.fr????\ot.ico
[%PROFILE_TEMP%]\temp.fr????\ts.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ot.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ts.ico
[%PROGRAM_FILES%]\Brain Codec\ot.ico
[%PROGRAM_FILES%]\Brain Codec\ts.ico
[%PROGRAM_FILES%]\EliteCodec\ot.ico
[%PROGRAM_FILES%]\EliteCodec\ts.ico
[%PROGRAM_FILES%]\Gold Codec\ot.ico
[%PROGRAM_FILES%]\Gold Codec\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ts.ico
[%PROGRAM_FILES%]\IntCodec\ot.ico
[%PROGRAM_FILES%]\IntCodec\ts.ico
[%PROGRAM_FILES%]\Internet Security\ot.ico
[%PROGRAM_FILES%]\Internet Security\ts.ico
[%PROGRAM_FILES%]\iVideoCodec\ot.ico
[%PROGRAM_FILES%]\iVideoCodec\ts.ico
[%PROGRAM_FILES%]\Key Generator\ot.ico
[%PROGRAM_FILES%]\Key Generator\ts.ico
[%PROGRAM_FILES%]\My Pass Generator\ot.ico
[%PROGRAM_FILES%]\My Pass Generator\ts.ico
[%PROGRAM_FILES%]\Online Add-on\ot.ico
[%PROGRAM_FILES%]\Online Add-on\ts.ico
[%PROGRAM_FILES%]\Online Image Add-on\ot.ico
[%PROGRAM_FILES%]\Online Image Add-on\ts.ico
[%PROGRAM_FILES%]\Online Video Add-on\ot.ico
[%PROGRAM_FILES%]\Online Video Add-on\ts.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ot.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ts.ico
[%PROGRAM_FILES%]\PCODEC\ot.ico
[%PROGRAM_FILES%]\PCODEC\ts.ico
[%PROGRAM_FILES%]\Perfect Codec\ot.ico
[%PROGRAM_FILES%]\Perfect Codec\ts.ico
[%PROGRAM_FILES%]\PornPass Manager\ot.ico
[%PROGRAM_FILES%]\PornPass Manager\ts.ico
[%PROGRAM_FILES%]\QualityCodec\ot.ico
[%PROGRAM_FILES%]\QualityCodec\ts.ico
[%PROGRAM_FILES%]\Security Tools\ot.ico
[%PROGRAM_FILES%]\Security Tools\ts.ico
[%PROGRAM_FILES%]\Silver Codec\ot.ico
[%PROGRAM_FILES%]\Silver Codec\ts.ico
[%PROGRAM_FILES%]\strCodec\ot.ico
[%PROGRAM_FILES%]\strCodec\ts.ico
[%PROGRAM_FILES%]\Super Codec\ot.ico
[%PROGRAM_FILES%]\Super Codec\ts.ico
[%PROGRAM_FILES%]\TrueCodec\ot.ico
[%PROGRAM_FILES%]\TrueCodec\ts.ico
[%PROGRAM_FILES%]\VidCodecs\ot.ico
[%PROGRAM_FILES%]\VidCodecs\ts.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ot.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ts.ico
[%PROGRAM_FILES%]\Video Add-on\ot.ico
[%PROGRAM_FILES%]\Video Add-on\ts.ico
[%PROGRAM_FILES%]\Video AX Object\ot.ico
[%PROGRAM_FILES%]\Video AX Object\ts.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ot.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ts.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ot.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ts.ico
[%PROGRAM_FILES%]\VideosCodec\ot.ico
[%PROGRAM_FILES%]\VideosCodec\ts.ico
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ot.ico
[%SYSTEM%]\ot.ico_wally
[%SYSTEM%]\ts.ico
[%SYSTEM%]\uvnx.exe
[%WINDOWS%]\msvb.dll
[%WINDOWS%]\netadv.dll
[%WINDOWS%]\sysdx.dll
[%WINDOWS%]\uwcwxwy.exe
[%DESKTOP%]\Online Security Guide.lnk
[%DESKTOP%]\SECURITY
[%DESKTOP%]\Security Troubleshooting.lnk
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%STARTMENU%]\Online Security Guide.url
[%STARTMENU%]\Security Troubleshooting.url
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ot.ico
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ts.ico
[%PROFILE_TEMP%]\sysmfd.exe
[%PROGRAM_FILES%]\Helper\yourprosearch.dll
[%SYSTEM%]\tvtpwp.dll
[%SYSTEM%]\ymmzwd.dll
[%WINDOWS%]\bndsrwlq.dll
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ot.ico
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ts.ico
[%DESKTOP%]\Viruz\temp.fr????\ot.ico
[%DESKTOP%]\Viruz\temp.fr????\ts.ico
[%PROFILE_TEMP%]\temp.fr????\ot.ico
[%PROFILE_TEMP%]\temp.fr????\ts.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ot.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ts.ico
[%PROGRAM_FILES%]\Brain Codec\ot.ico
[%PROGRAM_FILES%]\Brain Codec\ts.ico
[%PROGRAM_FILES%]\EliteCodec\ot.ico
[%PROGRAM_FILES%]\EliteCodec\ts.ico
[%PROGRAM_FILES%]\Gold Codec\ot.ico
[%PROGRAM_FILES%]\Gold Codec\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ts.ico
[%PROGRAM_FILES%]\IntCodec\ot.ico
[%PROGRAM_FILES%]\IntCodec\ts.ico
[%PROGRAM_FILES%]\Internet Security\ot.ico
[%PROGRAM_FILES%]\Internet Security\ts.ico
[%PROGRAM_FILES%]\iVideoCodec\ot.ico
[%PROGRAM_FILES%]\iVideoCodec\ts.ico
[%PROGRAM_FILES%]\Key Generator\ot.ico
[%PROGRAM_FILES%]\Key Generator\ts.ico
[%PROGRAM_FILES%]\My Pass Generator\ot.ico
[%PROGRAM_FILES%]\My Pass Generator\ts.ico
[%PROGRAM_FILES%]\Online Add-on\ot.ico
[%PROGRAM_FILES%]\Online Add-on\ts.ico
[%PROGRAM_FILES%]\Online Image Add-on\ot.ico
[%PROGRAM_FILES%]\Online Image Add-on\ts.ico
[%PROGRAM_FILES%]\Online Video Add-on\ot.ico
[%PROGRAM_FILES%]\Online Video Add-on\ts.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ot.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ts.ico
[%PROGRAM_FILES%]\PCODEC\ot.ico
[%PROGRAM_FILES%]\PCODEC\ts.ico
[%PROGRAM_FILES%]\Perfect Codec\ot.ico
[%PROGRAM_FILES%]\Perfect Codec\ts.ico
[%PROGRAM_FILES%]\PornPass Manager\ot.ico
[%PROGRAM_FILES%]\PornPass Manager\ts.ico
[%PROGRAM_FILES%]\QualityCodec\ot.ico
[%PROGRAM_FILES%]\QualityCodec\ts.ico
[%PROGRAM_FILES%]\Security Tools\ot.ico
[%PROGRAM_FILES%]\Security Tools\ts.ico
[%PROGRAM_FILES%]\Silver Codec\ot.ico
[%PROGRAM_FILES%]\Silver Codec\ts.ico
[%PROGRAM_FILES%]\strCodec\ot.ico
[%PROGRAM_FILES%]\strCodec\ts.ico
[%PROGRAM_FILES%]\Super Codec\ot.ico
[%PROGRAM_FILES%]\Super Codec\ts.ico
[%PROGRAM_FILES%]\TrueCodec\ot.ico
[%PROGRAM_FILES%]\TrueCodec\ts.ico
[%PROGRAM_FILES%]\VidCodecs\ot.ico
[%PROGRAM_FILES%]\VidCodecs\ts.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ot.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ts.ico
[%PROGRAM_FILES%]\Video Add-on\ot.ico
[%PROGRAM_FILES%]\Video Add-on\ts.ico
[%PROGRAM_FILES%]\Video AX Object\ot.ico
[%PROGRAM_FILES%]\Video AX Object\ts.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ot.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ts.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ot.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ts.ico
[%PROGRAM_FILES%]\VideosCodec\ot.ico
[%PROGRAM_FILES%]\VideosCodec\ts.ico
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ot.ico
[%SYSTEM%]\ot.ico_wally
[%SYSTEM%]\ts.ico
[%SYSTEM%]\uvnx.exe
[%WINDOWS%]\msvb.dll
[%WINDOWS%]\netadv.dll
[%WINDOWS%]\sysdx.dll
[%WINDOWS%]\uwcwxwy.exe
[%DESKTOP%]\Online Security Guide.lnk
[%DESKTOP%]\SECURITY
[%DESKTOP%]\Security Troubleshooting.lnk
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%STARTMENU%]\Online Security Guide.url
[%STARTMENU%]\Security Troubleshooting.url
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ot.ico
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ts.ico
[%PROFILE_TEMP%]\sysmfd.exe
[%PROGRAM_FILES%]\Helper\yourprosearch.dll
[%SYSTEM%]\tvtpwp.dll
[%SYSTEM%]\ymmzwd.dll
[%WINDOWS%]\bndsrwlq.dll

In order to ensure that the Zlob is launched automatically each time the system is booted, the Zlob adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%PROGRAM_FILES%]\Video ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video ActiveX Object\isamntr.exe
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\uvnx.exe
[%WINDOWS%]\uwcwxwy.exe
[%PROFILE%]\cmd.exe
[%PROFILE_TEMP%]\sysmfd.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Zlob:

Files:
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ot.ico
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ts.ico
[%DESKTOP%]\Viruz\temp.fr????\ot.ico
[%DESKTOP%]\Viruz\temp.fr????\ts.ico
[%PROFILE_TEMP%]\temp.fr????\ot.ico
[%PROFILE_TEMP%]\temp.fr????\ts.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ot.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ts.ico
[%PROGRAM_FILES%]\Brain Codec\ot.ico
[%PROGRAM_FILES%]\Brain Codec\ts.ico
[%PROGRAM_FILES%]\EliteCodec\ot.ico
[%PROGRAM_FILES%]\EliteCodec\ts.ico
[%PROGRAM_FILES%]\Gold Codec\ot.ico
[%PROGRAM_FILES%]\Gold Codec\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ts.ico
[%PROGRAM_FILES%]\IntCodec\ot.ico
[%PROGRAM_FILES%]\IntCodec\ts.ico
[%PROGRAM_FILES%]\Internet Security\ot.ico
[%PROGRAM_FILES%]\Internet Security\ts.ico
[%PROGRAM_FILES%]\iVideoCodec\ot.ico
[%PROGRAM_FILES%]\iVideoCodec\ts.ico
[%PROGRAM_FILES%]\Key Generator\ot.ico
[%PROGRAM_FILES%]\Key Generator\ts.ico
[%PROGRAM_FILES%]\My Pass Generator\ot.ico
[%PROGRAM_FILES%]\My Pass Generator\ts.ico
[%PROGRAM_FILES%]\Online Add-on\ot.ico
[%PROGRAM_FILES%]\Online Add-on\ts.ico
[%PROGRAM_FILES%]\Online Image Add-on\ot.ico
[%PROGRAM_FILES%]\Online Image Add-on\ts.ico
[%PROGRAM_FILES%]\Online Video Add-on\ot.ico
[%PROGRAM_FILES%]\Online Video Add-on\ts.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ot.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ts.ico
[%PROGRAM_FILES%]\PCODEC\ot.ico
[%PROGRAM_FILES%]\PCODEC\ts.ico
[%PROGRAM_FILES%]\Perfect Codec\ot.ico
[%PROGRAM_FILES%]\Perfect Codec\ts.ico
[%PROGRAM_FILES%]\PornPass Manager\ot.ico
[%PROGRAM_FILES%]\PornPass Manager\ts.ico
[%PROGRAM_FILES%]\QualityCodec\ot.ico
[%PROGRAM_FILES%]\QualityCodec\ts.ico
[%PROGRAM_FILES%]\Security Tools\ot.ico
[%PROGRAM_FILES%]\Security Tools\ts.ico
[%PROGRAM_FILES%]\Silver Codec\ot.ico
[%PROGRAM_FILES%]\Silver Codec\ts.ico
[%PROGRAM_FILES%]\strCodec\ot.ico
[%PROGRAM_FILES%]\strCodec\ts.ico
[%PROGRAM_FILES%]\Super Codec\ot.ico
[%PROGRAM_FILES%]\Super Codec\ts.ico
[%PROGRAM_FILES%]\TrueCodec\ot.ico
[%PROGRAM_FILES%]\TrueCodec\ts.ico
[%PROGRAM_FILES%]\VidCodecs\ot.ico
[%PROGRAM_FILES%]\VidCodecs\ts.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ot.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ts.ico
[%PROGRAM_FILES%]\Video Add-on\ot.ico
[%PROGRAM_FILES%]\Video Add-on\ts.ico
[%PROGRAM_FILES%]\Video AX Object\ot.ico
[%PROGRAM_FILES%]\Video AX Object\ts.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ot.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ts.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ot.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ts.ico
[%PROGRAM_FILES%]\VideosCodec\ot.ico
[%PROGRAM_FILES%]\VideosCodec\ts.ico
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ot.ico
[%SYSTEM%]\ot.ico_wally
[%SYSTEM%]\ts.ico
[%SYSTEM%]\uvnx.exe
[%WINDOWS%]\msvb.dll
[%WINDOWS%]\netadv.dll
[%WINDOWS%]\sysdx.dll
[%WINDOWS%]\uwcwxwy.exe
[%DESKTOP%]\Online Security Guide.lnk
[%DESKTOP%]\SECURITY
[%DESKTOP%]\Security Troubleshooting.lnk
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%STARTMENU%]\Online Security Guide.url
[%STARTMENU%]\Security Troubleshooting.url
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ot.ico
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ts.ico
[%PROFILE_TEMP%]\sysmfd.exe
[%PROGRAM_FILES%]\Helper\yourprosearch.dll
[%SYSTEM%]\tvtpwp.dll
[%SYSTEM%]\ymmzwd.dll
[%WINDOWS%]\bndsrwlq.dll
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ot.ico
[%COMMON_DOCUMENTS%]\Video ActiveX Object\ts.ico
[%DESKTOP%]\Viruz\temp.fr????\ot.ico
[%DESKTOP%]\Viruz\temp.fr????\ts.ico
[%PROFILE_TEMP%]\temp.fr????\ot.ico
[%PROFILE_TEMP%]\temp.fr????\ts.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ot.ico
[%PROFILE_TEMP%]\NoadwareBkupTemp\ts.ico
[%PROGRAM_FILES%]\Brain Codec\ot.ico
[%PROGRAM_FILES%]\Brain Codec\ts.ico
[%PROGRAM_FILES%]\EliteCodec\ot.ico
[%PROGRAM_FILES%]\EliteCodec\ts.ico
[%PROGRAM_FILES%]\Gold Codec\ot.ico
[%PROGRAM_FILES%]\Gold Codec\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Image ActiveX Object\ts.ico
[%PROGRAM_FILES%]\IntCodec\ot.ico
[%PROGRAM_FILES%]\IntCodec\ts.ico
[%PROGRAM_FILES%]\Internet Security\ot.ico
[%PROGRAM_FILES%]\Internet Security\ts.ico
[%PROGRAM_FILES%]\iVideoCodec\ot.ico
[%PROGRAM_FILES%]\iVideoCodec\ts.ico
[%PROGRAM_FILES%]\Key Generator\ot.ico
[%PROGRAM_FILES%]\Key Generator\ts.ico
[%PROGRAM_FILES%]\My Pass Generator\ot.ico
[%PROGRAM_FILES%]\My Pass Generator\ts.ico
[%PROGRAM_FILES%]\Online Add-on\ot.ico
[%PROGRAM_FILES%]\Online Add-on\ts.ico
[%PROGRAM_FILES%]\Online Image Add-on\ot.ico
[%PROGRAM_FILES%]\Online Image Add-on\ts.ico
[%PROGRAM_FILES%]\Online Video Add-on\ot.ico
[%PROGRAM_FILES%]\Online Video Add-on\ts.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ot.ico
[%PROGRAM_FILES%]\PCFree\Recovery\[2006-11-23]05_20_36_921\WINDOWS\system32\ts.ico
[%PROGRAM_FILES%]\PCODEC\ot.ico
[%PROGRAM_FILES%]\PCODEC\ts.ico
[%PROGRAM_FILES%]\Perfect Codec\ot.ico
[%PROGRAM_FILES%]\Perfect Codec\ts.ico
[%PROGRAM_FILES%]\PornPass Manager\ot.ico
[%PROGRAM_FILES%]\PornPass Manager\ts.ico
[%PROGRAM_FILES%]\QualityCodec\ot.ico
[%PROGRAM_FILES%]\QualityCodec\ts.ico
[%PROGRAM_FILES%]\Security Tools\ot.ico
[%PROGRAM_FILES%]\Security Tools\ts.ico
[%PROGRAM_FILES%]\Silver Codec\ot.ico
[%PROGRAM_FILES%]\Silver Codec\ts.ico
[%PROGRAM_FILES%]\strCodec\ot.ico
[%PROGRAM_FILES%]\strCodec\ts.ico
[%PROGRAM_FILES%]\Super Codec\ot.ico
[%PROGRAM_FILES%]\Super Codec\ts.ico
[%PROGRAM_FILES%]\TrueCodec\ot.ico
[%PROGRAM_FILES%]\TrueCodec\ts.ico
[%PROGRAM_FILES%]\VidCodecs\ot.ico
[%PROGRAM_FILES%]\VidCodecs\ts.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video Access ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Access\ts.ico
[%PROGRAM_FILES%]\Video ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Object\ot.ico
[%PROGRAM_FILES%]\Video ActiveX Object\ts.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ot.ico
[%PROGRAM_FILES%]\Video Add-on Setup\ts.ico
[%PROGRAM_FILES%]\Video Add-on\ot.ico
[%PROGRAM_FILES%]\Video Add-on\ts.ico
[%PROGRAM_FILES%]\Video AX Object\ot.ico
[%PROGRAM_FILES%]\Video AX Object\ts.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ot.ico
[%PROGRAM_FILES%]\VideoCompressionCodec\ts.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ot.ico
[%PROGRAM_FILES%]\VideoKeyCodec\ts.ico
[%PROGRAM_FILES%]\VideosCodec\ot.ico
[%PROGRAM_FILES%]\VideosCodec\ts.ico
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ot.ico
[%SYSTEM%]\ot.ico_wally
[%SYSTEM%]\ts.ico
[%SYSTEM%]\uvnx.exe
[%WINDOWS%]\msvb.dll
[%WINDOWS%]\netadv.dll
[%WINDOWS%]\sysdx.dll
[%WINDOWS%]\uwcwxwy.exe
[%DESKTOP%]\Online Security Guide.lnk
[%DESKTOP%]\SECURITY
[%DESKTOP%]\Security Troubleshooting.lnk
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%STARTMENU%]\Online Security Guide.url
[%STARTMENU%]\Security Troubleshooting.url
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ot.ico
[%PROFILE%]\Configuraci%F3n local\Temp\temp.fr????\ts.ico
[%PROFILE_TEMP%]\sysmfd.exe
[%PROGRAM_FILES%]\Helper\yourprosearch.dll
[%SYSTEM%]\tvtpwp.dll
[%SYSTEM%]\ymmzwd.dll
[%WINDOWS%]\bndsrwlq.dll

Folders:
[%PROGRAM_FILES%]\VideoAccessCodec
[%PROGRAM_FILES%]\Image Add-on
[%PROGRAM_FILES%]\Video Add-on

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}
HKEY_CLASSES_ROOT\vac.video
HKEY_LOCAL_MACHINE\software\microsoft\videoplugin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a43385f0-7113-496d-96d7-b9b550e3fcca}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoAccessCodec
HKEY_CLASSES_ROOT\clsid\{0b4fe923-0e04-4d8a-bc4f-db8c672a1584}
HKEY_CLASSES_ROOT\clsid\{0dfcfb5e-3974-3338-8f09-0b2552e546a8}
HKEY_CLASSES_ROOT\clsid\{a43385f0-7113-496d-96d7-b9b550e3fcca}
HKEY_CLASSES_ROOT\clsid\{b02534d7-8d91-49be-a864-97dfb8e0bab4}
HKEY_CLASSES_ROOT\clsid\{d8b937a4-cdad-497b-a872-8da7c4c3ef6f}
HKEY_CLASSES_ROOT\optnet.stockbar
HKEY_CLASSES_ROOT\optnet.toolbar.1
HKEY_CLASSES_ROOT\secmediaonline
HKEY_CLASSES_ROOT\vclsdcompression.class
HKEY_CLASSES_ROOT\videopl.chl
HKEY_CURRENT_USER\software\reknu
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0dfcfb5e-3974-3338-8f09-0b2552e546a8}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a43385f0-7113-496d-96d7-b9b550e3fcca}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\image add-on
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\multimedia software
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videoaccesscodec

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CLASSES_ROOT\clsid\{edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e}\inprocserver32
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Zlob:

An up-to-date copy of ExterminateIt should detect and prevent infection from Zlob.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Zlob manually.

To completely manually remove Zlob malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Zlob.

  1. Use Task Manager to terminate the Zlob process.
  2. Delete the original Zlob file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Zlob from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Zlob!


Also Be Aware of the Following Threats:
Fitmispani Hijacker Symptoms
Hupegion Trojan Removal instruction
Pigeon.AND Trojan Cleaner
Gonads Trojan Cleaner
Remove Win32.VB.apq Trojan

0 comments:

Post a Comment

Blog Archive