Virus: TR/Zlob.65745.8 Date discovered: 25/10/2006 Type: Trojan In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 49.803 Bytes MD5 checksum: eea22afe223ef4c31fd0442281eaae61 VDF version: 6.36.00.166 IVDF version: 6.36.00.184 - Monday, October 30, 2006
General Method of propagation: • No own spreading routine Aliases: • F-Secure: Trojan-Downloader.Win32.Zlob.aqo • Grisoft: Downloader.Zlob.CX • Eset: Win32/TrojanDownloader.Zlob Platforms / OS: • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops a malicious file • Registry modification Right after execution the following information is displayed: Files It creates the following directory: • %PROGRAM FILES% \VideoCompressionCodec The following file is created: – %PROGRAM FILES% \VideoCompressionCodec\uninst.exe Further investigation pointed out that this file is malware, too. Detected as: TR/Zlob.65745.8 It tries to download some files: – The location is the following: • 85.255.118.2/ultra/php/install/********** It is saved on the local hard drive under: %TEMPDIR% \laf%hex number% .tmp Furthermore this file gets executed after it was fully downloaded. – The location is the following: • yourguardonline.biz/********** It is saved on the local hard drive under: %TEMPDIR% \laf%hex number% .tmp Furthermore this file gets executed after it was fully downloaded. This file may contain further download locations and might serve as source for new threats. – The location is the following: • 85.255.118.2/ultra/php/install/********** It is saved on the local hard drive under: %TEMPDIR% \laf%hex number% .tmp Furthermore this file gets executed after it was fully downloaded. Registry The following registry keys are added: – [HKCU\Software\Internet Security] • "Type"=dword:00000003 • "Path"="%PROGRAM FILES% \VideoCompressionCodec" • "Removable"=dword:00000000 – [HKCR\VSEnchancer.Chl] – [HKCR\VSEnchancer.Chl\CLSID] • @="{6BF52A52-394A-11D3-B153-00C04F79FAA6}" – [HKCR\AVZipEnchancer.Chl] – [HKCR\AVZipEnchancer.Chl\CLSID] • @="{6BF52A52-394A-11D3-B153-00C04F79FAA6}" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ VideoCompressionCodec] • "ProductionEnvironment"="1" • "DisplayName"="VideoCompressionCodec 10.0" • "UninstallString"="%PROGRAM FILES% \VideoCompressionCodec\uninst.exe" • "DisplayIcon"="%PROGRAM FILES% \VideoCompressionCodec\uninst.exe" • "DisplayVersion"="10.0" • "URLInfoAbout"="www.vccodec.com" • "Publisher"="VideoCompressionCodec Software" File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX
Description inserted by Adriana Popa on Monday, November 13, 2006 Description updated by Adriana Popa on Tuesday, November 21, 2006
Back
.
.
.
.