Trojan

TrojanDownloader:Win32/Zlob.AMP removal tips

Malware Removal

The TrojanDownloader:Win32/Zlob.AMP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zlob.AMP virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine TrojanDownloader:Win32/Zlob.AMP?


File Info:

name: 18AF64F6DB0416842B06.mlw
path: /opt/CAPEv2/storage/binaries/516f73e12385a3e8f0b79e4e04704cbc41bba094f7d369ce2b6d93311ac43912
crc32: D4692B33
md5: 18af64f6db0416842b06af2944b6b2b1
sha1: 0ba495aa7a0eac0db85c29ae08346b63afe205ae
sha256: 516f73e12385a3e8f0b79e4e04704cbc41bba094f7d369ce2b6d93311ac43912
sha512: 6fd90d10a6f2dc42d860bb87f5f0cb75e8775ecd2f8c1e2076d55aac515f6ca62a7ce3ed802c25eab88a6b5a7a8a32c50cd02d6e37b0001eb36a2893639298fa
ssdeep: 384:9EYT+T1A3CxdeaDi4UGxWKsEX2TtW3+n:9dT+RUnKsEO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C942AD2FF3086BC7D0965733221B472A09DAADF84338FB194804705BF269AF83699434
sha3_384: 93afd8106300ceb5d9a8e9c691d4bd32c9502d767af3485d9e9b577470c2eee9dfd8e8362d471e7d71be624bf26d6135
ep_bytes: 60be007040008dbe00a0ffff57eb0b90
timestamp: 2008-04-04 09:04:49

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zlob.AMP also known as:

MicroWorld-eScanGen:Trojan.Heur.amGfrT3KmEncu
ClamAVWin.Trojan.Zlob-4932
FireEyeGeneric.mg.18af64f6db041684
CAT-QuickHealDownloader.Zlob.8145
ALYacGen:Trojan.Heur.amGfrT3KmEncu
CylanceUnsafe
VIPREGen:Trojan.Heur.amGfrT3KmEncu
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
VirITTrojan.Win32.ZLOB
CyrenW32/Downldr2.BMKO
SymantecTrojan.Zlob
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Zlob.BTE
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Downloader.Win32.Zlob.lps
BitDefenderGen:Trojan.Heur.amGfrT3KmEncu
NANO-AntivirusTrojan.Win32.Zlob.wtzr
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c3587
Ad-AwareGen:Trojan.Heur.amGfrT3KmEncu
SophosML/PE-A + Troj/ZlobPx-Gen
ComodoTrojWare.Win32.TrojanDownloader.Zlob.BTE@as5s
DrWebTrojan.DownLoader.63612
ZillyaDownloader.Zlob.Win32.9786
TrendMicroTROJ_ZLOB.EWP
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lh
EmsisoftGen:Trojan.Heur.amGfrT3KmEncu (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur.amGfrT3KmEncu
JiangminTrojanDownloader.Zlob.hyq
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1BB
KingsoftWin32.Troj.ZlobT.xr.40960.(kcloud)
ArcabitTrojan.Heur.amGfrT3KmEncu
MicrosoftTrojanDownloader:Win32/Zlob.AMP
GoogleDetected
AhnLab-V3Win-Trojan/Zlob6.Gen
McAfeegeneric!bg
MAXmalware (ai score=81)
VBA32TrojanDownloader.Zlob
MalwarebytesMalware.AI.1744106140
TrendMicro-HouseCallTROJ_ZLOB.EWP
RisingMalware.Undefined!8.C (TFE:5:sti4ippiEVD)
YandexTrojan.GenAsa!wxICTJruug0
IkarusTrojan.Zlob
FortinetW32/Zlob.RF!tr
BitDefenderThetaAI:Packer.E041B24B1D
AVGWin32:Malware-gen
Cybereasonmalicious.6db041
PandaAdware/Netproject

How to remove TrojanDownloader:Win32/Zlob.AMP?

TrojanDownloader:Win32/Zlob.AMP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment