Trojan

TrojanDownloader:Win32/Zlob.TU malicious file

Malware Removal

The TrojanDownloader:Win32/Zlob.TU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zlob.TU virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:Win32/Zlob.TU?


File Info:

crc32: 6D537309
md5: dd15de9c69d78fef00457a1359e4c9c5
name: DD15DE9C69D78FEF00457A1359E4C9C5.mlw
sha1: 24b51e560a4eadf5e789e933aafbb9ec6c477391
sha256: ddadad6f07b2ee19007652d8f47912d932e4ab8780fe5826d45c9d1d7e9f0541
sha512: ef39801de1b6599fd1ff6b0b4d8d904511526fc2539600d1020c1f34841b1f106abf285c3eb9694634d546cc019c690ed7b245a197a6f4c6a755598335f38cd8
ssdeep: 1536:4tVRpxjnaaGKsUesJ62FISkiIvNQRwc0cjZq4:4vnBaaWOJxIBVcB84
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zlob.TU also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Popuper
MicroWorld-eScanDeepScan:Generic.Zlob.DCF3AC6B
FireEyeDeepScan:Generic.Zlob.DCF3AC6B
McAfeeArtemis!DD15DE9C69D7
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusTrojan-Downloader ( 00561d4c1 )
BitDefenderDeepScan:Generic.Zlob.DCF3AC6B
K7GWTrojan-Downloader ( 00561d4c1 )
Cybereasonmalicious.c69d78
BitDefenderThetaGen:NN.ZedlaF.34804.bq4@auvoIcf
CyrenW32/Zlob.R.gen!Eldorado
SymantecTrojan.Zlob
TotalDefenseWin32/Nuvens!generic
TrendMicro-HouseCallTROJ_ZLOB.AUU
Paloaltogeneric.ml
ClamAVWin.Downloader.Zlob-2062
NANO-AntivirusTrojan.Win32.Zlob.cqpcxx
RisingTrojan.DL.Zlob.GEN (CLASSIC:bWQ1OvAWGATrpFLK3n/ROGhR12w)
Ad-AwareDeepScan:Generic.Zlob.DCF3AC6B
EmsisoftDeepScan:Generic.Zlob.DCF3AC6B (B)
ComodoTrojWare.Win32.Zlob.65536_10@1mjeff
F-SecureTrojan.TR/Drop.Zlob.CJ.2
ZillyaDownloader.ZlobCRTD.Win32.2997
TrendMicroTROJ_ZLOB.AUU
McAfee-GW-EditionPuper.fd
SophosTroj/Zlobar-Fam
IkarusTrojan-Downloader.Win32.Zlob
JiangminTrojanDownloader.Zlob.bme
AviraTR/Zlob.65536.1
MAXmalware (ai score=89)
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
MicrosoftTrojanDownloader:Win32/Zlob.TU
ArcabitDeepScan:Generic.Zlob.DCF3AC6B
SUPERAntiSpywareTrojan.Media-Codec
ZoneAlarmHEUR:Trojan.Win32.Bsymem.gen
GDataDeepScan:Generic.Zlob.DCF3AC6B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zlob.R8906
VBA32Trojan-Downloader.Win32.Revelation.Zlob
ALYacDeepScan:Generic.Zlob.DCF3AC6B
MalwarebytesMalware.AI.706277642
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Zlob.ACK
TencentWin32.Trojan-downloader.Zlob.Wrqb
YandexTrojan.DL.Zlob.YL.Gen
eGambitUnsafe.AI_Score_100%
FortinetW32/Zlob.A!tr
PandaAdware/EMediaCodec
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Malware.Radar01.Gen

How to remove TrojanDownloader:Win32/Zlob.TU?

TrojanDownloader:Win32/Zlob.TU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment