Trojan

TrojanDownloader:Win32/Zlob.BAF malicious file

Malware Removal

The TrojanDownloader:Win32/Zlob.BAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zlob.BAF virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings

Related domains:

www.bing.com

How to determine TrojanDownloader:Win32/Zlob.BAF?


File Info:

crc32: 7FDD51D7
md5: 7248beb252a8e682ae2f8d939081f52f
name: 7248BEB252A8E682AE2F8D939081F52F.mlw
sha1: 645ad86fd768c458577ef56f45e340110173e665
sha256: 5b678735f75a86b7bb6d6ed379c3983cde7cba9104ac7e3d1a1fd36c33707cfb
sha512: 7ba10c8cc1706386b4531bc480e57265ced56b567aa34b9f64a3286ac9784f71bd54ceeaf75f985cb22fa26f8ca60ee899824995e6a5c6862329592ceb1b6ca5
ssdeep: 1536:N4eEkOCozGzDH0eyiDiKufgBR9DPoz5WZKsQl:N4M8Gv2PKuqRgoZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zlob.BAF also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanDeepScan:Generic.Zlob.8E7078AA
FireEyeGeneric.mg.7248beb252a8e682
McAfeeArtemis!7248BEB252A8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
BitDefenderDeepScan:Generic.Zlob.8E7078AA
Cybereasonmalicious.252a8e
CyrenW32/Zlob.Y.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Puper!generic
APEXMalicious
AvastFileRepMalware
ClamAVWin.Adware.BHO-4656
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Zlob.cwoixk
Ad-AwareDeepScan:Generic.Zlob.8E7078AA
EmsisoftDeepScan:Generic.Zlob.8E7078AA (B)
ComodoMalware@#30mfpsuzh5bjj
F-SecureAdware.ADSPY/SecuriToolBar
DrWebTrojan.Popuper.7005
ZillyaDownloader.Zlob.Win32.31645
TrendMicroMal_Zlob-7
McAfee-GW-EditionBehavesLike.Win32.Dropper.kc
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Zlob.zsv
WebrootW32.Malware.Gen
AviraADSPY/SecuriToolBar
MicrosoftTrojanDownloader:Win32/Zlob.BAF
ArcabitDeepScan:Generic.Zlob.8E7078AA
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Zlob.8E7078AA
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.BFC7417520
MAXmalware (ai score=88)
VBA32TrojanDownloader.Zlob
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Zlob.NCS
TrendMicro-HouseCallMal_Zlob-7
RisingMalware.Generic.5!tfe (C64:YzY0OlWHj3HHTGIo)
YandexTrojan.GenAsa!pe+5kx0RrvQ
Ikarusnot-a-virus:AdWare.Win32.Agent
FortinetW32/Puper.ABS!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.af2

How to remove TrojanDownloader:Win32/Zlob.BAF?

TrojanDownloader:Win32/Zlob.BAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment