Trojan

MemScan:Trojan.Zlob.28359 removal guide

Malware Removal

The MemScan:Trojan.Zlob.28359 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Zlob.28359 virus can do?

  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MemScan:Trojan.Zlob.28359?


File Info:

name: 9C9FE48453D5B175B669.mlw
path: /opt/CAPEv2/storage/binaries/d555a9b7768ce19b6c4ec09e200b6531ca820f31fee5ffc87c54b3e248cf18cf
crc32: E47CCEF5
md5: 9c9fe48453d5b175b6695efcbecd83e5
sha1: d42f1790f0ee58bc0bd9fdb1cdffa3d80f5daa07
sha256: d555a9b7768ce19b6c4ec09e200b6531ca820f31fee5ffc87c54b3e248cf18cf
sha512: a38f3c05a6e30974229dfd1109dd2df6cac00b248b386f7916bb838010feca145886c926f555d16ae082adb0aa5bca90d570107a43ef764f2418496eacaa8d57
ssdeep: 768:Zyvky9IhMbzJVgJKI29/4mxPnbcuyD7U:Z6kyWMTgJKlJxPnouy8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5C27E5FD65C4AB2D7F90075089E291B3F72A0794349FED3CAC4609AE892BD0D52C18E
sha3_384: 3aa390804f4e54c0a06dcb61b243991885e1aad8427c9e8d4501e5acfbb973b7f06a565aecdab33c584d21cab62d35c2
ep_bytes: 33c050505050ff156430400050e8d911
timestamp: 2008-04-07 19:52:18

Version Info:

0: [No Data]

MemScan:Trojan.Zlob.28359 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zlob.kZeN
MicroWorld-eScanMemScan:Trojan.Zlob.28359
FireEyeGeneric.mg.9c9fe48453d5b175
McAfeeGenericRXAA-AA!9C9FE48453D5
MalwarebytesGeneric.Malware/Suspicious
ZillyaDownloader.Zlob.Win32.16056
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00036a7e1 )
BitDefenderMemScan:Trojan.Zlob.28359
K7GWTrojan-Downloader ( 00036a7e1 )
Cybereasonmalicious.0f0ee5
ArcabitTrojan.Zlob.D6EC7
BitDefenderThetaAI:Packer.BD5A31091C
CyrenW32/Downloader.AGUJ-2763
SymantecTrojan.Zlob
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Zlob.BTL
APEXMalicious
ClamAVWin.Downloader.96149-1
KasperskyTrojan-Downloader.Win32.Zlob.lps
AlibabaTrojanDownloader:Win32/Zlobmi.1f7bdf2e
NANO-AntivirusTrojan.Win32.Zlob.uyrp
ViRobotTrojan.Win32.Z.Zlob.27136.P
RisingDownloader.Zlob!8.B37 (TFE:3:lEnGJt305wT)
TACHYONTrojan-Clicker/W32.Zlob.27136.L
SophosTroj/Zlobmi-Gen
F-SecureTrojan.TR/Zlob.JW
DrWebTrojan.MulDrop5.10241
VIPREMemScan:Trojan.Zlob.28359
TrendMicroMal_Zlob-6
McAfee-GW-Editiongeneric!bg.ftt
Trapminemalicious.high.ml.score
EmsisoftMemScan:Trojan.Zlob.28359 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Zlob.iag
GoogleDetected
AviraTR/Zlob.JW
Antiy-AVLTrojan[Downloader]/Win32.Zlob
KingsoftWin32.Troj.Undef.a
XcitiumSuspicious@#2d0a0p300p9ja
MicrosoftTrojanDownloader:Win32/Zlob
ZoneAlarmTrojan-Downloader.Win32.Zlob.lps
GDataMemScan:Trojan.Zlob.28359
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Zlob.C82076
ALYacMemScan:Trojan.Zlob.28359
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32BScope.TrojanDownloader.Zlob
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallMal_Zlob-6
TencentWin32.Trojan-Downloader.Zlob.Vimw
YandexTrojan.GenAsa!xyRwuCZmYvw
IkarusTrojan.Zlob
MaxSecureTrojan.Malware.950917.susgen
FortinetW32/ZLOB.AL!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MemScan:Trojan.Zlob.28359?

MemScan:Trojan.Zlob.28359 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment