Trojan

TrojanDownloader.Zlob removal

Malware Removal

The TrojanDownloader.Zlob is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader.Zlob virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDownloader.Zlob?


File Info:

name: 7510229F726754CDA9A2.mlw
path: /opt/CAPEv2/storage/binaries/471603e2b3d4dc26c5e1f8a585707b3d0980ac8144789ca80bb5f45c058a7782
crc32: B01EDE1E
md5: 7510229f726754cda9a2a91bc5c50642
sha1: f6ef63ede66099fed87399272d241c68af2db3ee
sha256: 471603e2b3d4dc26c5e1f8a585707b3d0980ac8144789ca80bb5f45c058a7782
sha512: a38ae42e3ae5f0a6a7fb4df71074607adb220953bcb44d06434a803ca3228f40c55c19a0910839613707ecb9454f970dc210bd738c820de8b81365cd65585aa1
ssdeep: 6144:LwOKAqultqZ3jMRoSm8eY1QcVYD0zyFOpxqfXxUl:LwOzPFoSjL+FOpxEW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC547BD2EA0844CBFAEE213604275BA635E634FE97B4066A55DEF21F44132C24467CFA
sha3_384: 2fef570212908fd0a376c6469ba72f50ff1493f9fe1e108183f9bc3d94b0ab218ccb1628ccdcab78579777994dc43475
ep_bytes: 60be00a044008dbe0070fbff5789e58d
timestamp: 2002-02-05 13:09:00

Version Info:

0: [No Data]

TrojanDownloader.Zlob also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.7510229f726754cd
McAfeeArtemis!7510229F7267
MalwarebytesMalware.AI.3803524176
K7AntiVirusUnwanted-Program ( 004b9ffb1 )
K7GWUnwanted-Program ( 004b9ffb1 )
Cybereasonmalicious.de6609
BitDefenderThetaGen:NN.ZexaF.34114.rmGfaybhy8mi
SymantecW32.Virut.CF
ESET-NOD32a variant of Win32/HackTool.Patcher.D potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OA322
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Patched-AFV [Trj]
TencentWin32.Virus.Virut.Aexk
TrendMicroTROJ_GEN.R002C0OA322
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosGeneric PUA PG (PUA)
SentinelOneStatic AI – Malicious PE
JiangminHackTool/Kiser.fo
AviraHEUR/AGEN.1134284
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanDownloader.Zlob
CylanceUnsafe
APEXMalicious
YandexTrojan.GenAsa!BC+AHnCi2yQ
IkarusTrojan.Win32.Spy
eGambitUnsafe.AI_Score_99%
AVGWin32:Patched-AFV [Trj]

How to remove TrojanDownloader.Zlob?

TrojanDownloader.Zlob removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment