Threat behavior
Trojan:Win32/Zlob.gen!H is a generic detection for a component of the greater Win32/Zlob malware family. Win32/Zlob refers to a large multi-component family of malware that modifies Internet Explorer's settings, alters and redirects the user's default Internet search page and home page, and attempts to download and execute arbitrary files (including additional malicious software). The Win32/Zlob family has also been associated with rogue security programs that display misleading warnings regarding bogus malware infections.
Installation
Trojan:Win32/Zlob.gen!H may be downloaded and installed by other members of this large family, masquerading as a Video Codec kit. The file names used during installation vary among iterations of this threat. This trojan is a Web Browser Helper Object (BHO), distributed as a DLL.
After the DLL is written to the local system, it is registered via the Windows utility 'regsvr32.exe' using the '/s' parameter. The '/s' parameter instructs 'regsvr32' to run silently and to not display any message boxes. The registry may also be modified to run Win32/Zlob at each Windows start.
During installation of the BHO, it may add one of the following unique CLSID values:
{18DC3D52-5000-45BE-A4B8-BB9910758EE9}
{1C28A9A9-8704-4F4A-93B9-7983115F6E10}
{4BF7B3BF-B8B5-439D-A9EB-9272CB92186F}
{4C0C8119-1DF3-43EB-9551-B58AF1E04CA9}
{5A5817AC-C117-4FF6-A3DA-13142F6F6C5C}
{606C68BF-D3B8-49DC-9CEE-135B19698E93}
{76F30661-76C7-48CD-B18E-64F388AE030B}
{81F4697D-617D-40B4-85BA-C7684D9BC543}
{AE829A0E-DEC8-4146-9959-C054CBD4ECE6}
{BA06C18F-C952-4BC7-BED6-00EEB2BA8C2A}
{C1AEEDB2-C2BA-4F27-B591-44EA89388299}
{D7C622D9-8999-4FDF-81EB-E6B0A547FA61}
{F4DE1459-9941-48DB-AEFF-88A903379276}
{FDC5F6BF-F822-47EE-A03D-8158DF526AC9}
To subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_CLASSES_ROOT\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
HKEY_CLASSES_ROOT\MSVPS.MSVPSApp
HKEY_LOCAL_MACHINE\MSVPS.MSVPSApp
Payload
Redirects Web Traffic
When Internet Explorer is launched, the Zlob BHO may contact 'directnameservice.com' and retrieve a list of domains that the trojan may then redirect.
Displays False/Misleading MessagesWin32/Zlob.gen!H may display a false warning message at the top of the page with the following text:
"Warning: possible spyware or adware infection! Click here to scan your computer for spyware or adware…"
If a user clicks on the embedded link, they will be directed to a rogue security software webpage named 'trustedantivirus.com'.
Analysis by Andrei Florin Saygo
Prevention