Trojan

TrojanDownloader:Win32/Zlob.AMV removal

Malware Removal

The TrojanDownloader:Win32/Zlob.AMV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zlob.AMV virus can do?

  • Uses Windows utilities for basic functionality
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDownloader:Win32/Zlob.AMV?


File Info:

name: A1B6BF7DEF752DD138F5.mlw
path: /opt/CAPEv2/storage/binaries/628138736f91f06177ea7d75ee8cccff90c89bafe690c33abea5463e8d228b62
crc32: 8C4CFB74
md5: a1b6bf7def752dd138f5b232f1073774
sha1: 7bf69e2583ce40a5f6687458050735ab7895a8a0
sha256: 628138736f91f06177ea7d75ee8cccff90c89bafe690c33abea5463e8d228b62
sha512: a9c183501d842fda959d7b9d99e2c53c1dd02760f9d6511b4a3ed2d6736e42b5843aed34162e7464c3f81da335dac01e062d46ac325c7fabf0623767d893f84b
ssdeep: 1536:mIWxjcKbHYUMY6YOsQyp7QclzXiNuQYe0XiN:ujcKbHYUMFfsQ47BlzXi4xVXi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1958394B97AD58E10E8BA8031446F7AA9FF3A04B7F3059163DF414E92DDB5049A4AF0CD
sha3_384: 254cc8a3bba5e751027437e619c16a70a92647a75597fb8012715254f8c3cbc5a85abe1b88086056cc906a80df44c94a
ep_bytes: e81a00000033c050505050ff15707040
timestamp: 2008-09-28 17:21:19

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zlob.AMV also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
FireEyeGeneric.mg.a1b6bf7def752dd1
SkyhighBehavesLike.Win32.Generic.mt
McAfeeFakeAV-BE.gen
Cylanceunsafe
VIPREGen:Heur.Mint.Zard.24
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.583ce4
SymantecTrojan.Zlob
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Zlob.CUG
APEXMalicious
ClamAVWin.Trojan.Agent-102870
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
NANO-AntivirusTrojan.Win32.Agent.cwlhpn
MicroWorld-eScanGen:Heur.Mint.Zard.24
AvastWin32:DropperX-gen [Drp]
EmsisoftGen:Heur.Mint.Zard.24 (B)
F-SecureTrojan.TR/Dldr.Zlob.grs
DrWebTrojan.Fakealert.origin
TrendMicroMal_Zlob-8
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Zlob
GDataGen:Heur.Mint.Zard.24
JiangminTrojanDownloader.Zlob.zyx
GoogleDetected
AviraTR/Dldr.Zlob.grs
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.TrojDownloader.ZlobT.cd.45056
ArcabitTrojan.Mint.Zard.24
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Zlob.AMV
VaristW32/FakeAlert.O.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5593142
BitDefenderThetaGen:NN.ZexaF.36744.fyW@aaN5YJci
MAXmalware (ai score=81)
VBA32Malware-Cryptor.2LA.gen
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Zlob-8
RisingTrojan.Win32.Small.zza (CLASSIC)
YandexTrojan.Zlob.Gen.55
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Puper.ABS!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove TrojanDownloader:Win32/Zlob.AMV?

TrojanDownloader:Win32/Zlob.AMV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment