Trojan

Should I remove “Trojan.Zlob.65536.AA”?

Malware Removal

The Trojan.Zlob.65536.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zlob.65536.AA virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Zlob.65536.AA?


File Info:

name: EAE1204024C471BAC4A8.mlw
path: /opt/CAPEv2/storage/binaries/3b341fa73eb4c2a1ed5ecd2037fb7146ca5a29ff2223d3dcc21d7b681a5446e2
crc32: 0A1E398E
md5: eae1204024c471bac4a8075e1d84d503
sha1: d31400507ac4ca9d037696e3e2fc18d8d8f9a590
sha256: 3b341fa73eb4c2a1ed5ecd2037fb7146ca5a29ff2223d3dcc21d7b681a5446e2
sha512: a22bd62538ffce22fd159e900788a5d916efbdb023f81f97d14dce25c6c3e7278e2cb1c6b16295a109e203b4c23b662c7874871de7db352adf38b99275798638
ssdeep: 768:L2d/1YcVRHJxjnaDOGKiFdWzt/vuBIP/CrJ2s:AtVRpxjnaaGKsUz9TP/CL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16ED2E0D7F1105D54E8BEA2721F5FD4C4128C029296C8875D0F863FA7FAA32A476CEA16
sha3_384: 6fe81a0fe04f64338fc50dd4d33ecd14fef9a5ff260c5fbf41f1026e14bca4efbb69200093e808138a9dbb0829813612
ep_bytes: 60be00d042008dbe0040fdff5783cdff
timestamp: 2006-09-09 14:44:18

Version Info:

0: [No Data]

Trojan.Zlob.65536.AA also known as:

BkavW32.VideosCodecAJ.Adware
MicroWorld-eScanTrojan.Zlob.65536.AA
ALYacTrojan.Zlob.65536.AA
CylanceUnsafe
BitDefenderTrojan.Zlob.65536.AA
Cybereasonmalicious.024c47
CyrenW32/Zlob.R.gen!Eldorado
SymantecTrojan.Emcodec.E
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Zlob.DAV
TrendMicro-HouseCallTROJ_ZLOB.AXS
ClamAVWin.Trojan.Zlob-14729
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Nsis.Agent.fpfxcm
Ad-AwareTrojan.Zlob.65536.AA
SophosML/PE-A + Mal/Agent-ATY
ComodoTrojWare.Win32.Zlob.65536_20@1mjefg
TrendMicroTROJ_ZLOB.AXS
McAfee-GW-EditionBehavesLike.Win32.BadFile.mc
FireEyeTrojan.Zlob.65536.AA
EmsisoftTrojan.Zlob.65536.AA (B)
IkarusTrojan.Zlob
GDataTrojan.Zlob.65536.AA
AviraTR/Zlob.65536.2
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Zlob.R8906
McAfeeArtemis!EAE1204024C4
PandaAdware/StrCodec
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NAK!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Zlob.65536.AA?

Trojan.Zlob.65536.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment