Trojan

Should I remove “TrojanDownloader:Win32/Zlob.ANS”?

Malware Removal

The TrojanDownloader:Win32/Zlob.ANS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zlob.ANS virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
www.gatewp.com
gateqy.com

How to determine TrojanDownloader:Win32/Zlob.ANS?


File Info:

crc32: 360701BC
md5: 7887a850a50f03699336a760756640dc
name: 7887A850A50F03699336A760756640DC.mlw
sha1: 51f89d8f8fb0f78c9b50a2939e41ee37b011cb22
sha256: 21782dd51d439606eb5e5bb0025f5a4e7a946e284f108e945e76c902f79772e5
sha512: 3c2870178eb4cb05dc25c3e770a3a0395f1540f04f94d886ae1c937da9b2f51cbbec61e994f60bda2dabe88dd9ea6e0dc4ebeafd43d2d7079ac449d5cc95a364
ssdeep: 1536:v0FF3H2cMw+yRKZ9rqs/nouy8OcKYc/Nnouy8:cF3H29w3RW9OsvoutOc61out
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zlob.ANS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Zlob.kZyy
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.660
CynetMalicious (score: 100)
ALYacTrojan.Downloader.Zlob.ABRP
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.100642
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDownloader:Win32/Zlobmi.85895eff
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.0a50f0
CyrenW32/FakeAlert.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Zlob.BSF
APEXMalicious
AvastWin32:Zlob-BVQ [Trj]
ClamAVWin.Trojan.Zlob-2208
KasperskyTrojan-Downloader.Win32.Zlob.lps
BitDefenderTrojan.Downloader.Zlob.ABRP
NANO-AntivirusTrojan.Win32.Zlob.lhlu
MicroWorld-eScanTrojan.Downloader.Zlob.ABRP
TencentWin32.Trojan-downloader.Zlob.Aisd
Ad-AwareTrojan.Downloader.Zlob.ABRP
SophosML/PE-A + Troj/Zlobmi-Gen
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.79BBC2F31F
VIPREBehavesLike.Win32.Malware.bse (vs)
TrendMicroTROJ_ZLOB.BCG
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.km
FireEyeGeneric.mg.7887a850a50f0369
EmsisoftTrojan.Downloader.Zlob.ABRP (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Zlob.hjq
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.92EDB4
MicrosoftTrojanDownloader:Win32/Zlob.ANS
ArcabitTrojan.Downloader.Zlob.ABRP
SUPERAntiSpywareTrojan.Agent/Gen-Zlob
GDataTrojan.Downloader.Zlob.ABRP
AhnLab-V3Trojan/Win32.Zlob.C67568
Acronissuspicious
McAfeeGenericRXAA-FA!7887A850A50F
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Zlob
MalwarebytesMalware.AI.3849385929
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_ZLOB.BCG
RisingTrojan.DL.Win32.Zlob.GEN (CLASSIC)
YandexTrojan.Gavec!X2gpM6q/ZCw
IkarusTrojan-Downloader.Win32.Zlob
FortinetW32/ZLOB.AL!tr
AVGWin32:Zlob-BVQ [Trj]

How to remove TrojanDownloader:Win32/Zlob.ANS?

TrojanDownloader:Win32/Zlob.ANS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment