Threat behavior
TrojanDownloader:Win32/Zlob.gen!O is a generic detection of a component of the greater Win32/Zlob malware family. Win32/Zlob refers a large multi-component family of malware that modifies Internet Explorer's settings, alters and redirects the user's default Internet search page and home page, and attempts to download and execute arbitrary files (including additional malicious software). The Win32/Zlob family has also been associated with rogue security programs that display misleading warnings regarding bogus malware infections.
Installation
This Trojan is present on a system in the form of installed components that function as Web Browser Helper Objects (BHOs). This threat exists on malicious Web sites as a codec, or video "add on". Components may exist on a system as dynamic link library (DLL) files, such as "iesplugin.dll".
Example registry keys created during the installation of this Trojan:
HKEY_CURRENT_USER\Software\Classes\CLSID\{84938242-5C5B-4A55-B6B9-A1507543B418}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
{84938242-5C5B-4A55-B6B9-A1507543B418}
Additional Information
One example of this Trojan exists as a file named "Online_Video_Add_on.zip", and it contains several files that are detected with current signatures.
Online_Video_Add_On.zip contains:
icmntr.exe - detected as TrojanDownloader:Win32/Zlob.gen!O
icthis.exe - detected as TrojanDownloader:Win32/Zlob.gen!P
ictmdl.dll - detected as TrojanDownloader:Win32/Zlob.gen!Z
ictun.exe - detected as TrojanDownloader:Win32/Zlob.gen!H
isfmdl.dll - detected as TrojanDownloader:Win32/Zlob.gen!T
isfmm.exe - detected as TrojanDownloader:Win32/Zlob.gen!O
isfmntr.exe - detected as TrojanDownloader:Win32/Zlob.gen!O
This threat may pose as a legitimate application such as a password manager, or other application required for viewing adult content.
Prevention