Zlob - How to remove May 4, 2007 By Giedrius Majauskas Zlob is a backdoor Trojan that grants attackers control over the system, and allows them to perform malicious actions on the compromised computer – change essential system settings and modify certain files. However, the most well-known function of Zlob is to spread dangerous rogue anti-spyware parasites, such as SpyLocked and SpyLocker. Zlob is closely connected to these threats, and it is safe to say that if you detect Zlob on your system, these other parasites are almost certainly lurking somewhere on your PC, and vice versa. Zlob installs on infected system in very specific way : it pretends being an ActiveX driver or a video codec that is required for displaying video. After you download that codec and install it, the video fails to run anyways, but then it is too late and PC is already infected. That is why it might be detected as Zlob.Mediacodec or similar by some antiviruses(Wikipedia). The first version of Zlob Trojan was released in 2005 and it gained popularity together with rise of rogue antiviruses: its install technique is not very subtile one and could rise some suspicion and scans with anti-malware programs. Thus rogues were perfect way to make fast money from infection and even got credibility for being able to detect an infection very fast. Although Trojan.Zlob comes under several versions or names, some of them are incorrect. For example, Zlob.Sunporn originates from the way non-rootkit version of Zlob trojan installs in the system : It creates a subfolder in C:\Programs and Files\ from a predefined list of names. One of these names is SunPorn – a porn site, that has its own downloader. Other names include various codec names (like silver codec, qualtiy codec, perfect codec, pcodec), or other names related to videos software. Although Zlob is distributed through fake porn sites, SunPorn is not one of the sites distributing this malware. Some versions were used in the fake detections of the rogue antiviruses themselves. For example, Trojan.Zlob.Porn.Ad. These detections can be discarded : rogue antiviruses do not detect actual parasites and you will have to re-scan with actual anti-malware or antivirus program. Zlob is closely related to DNSChanger malware, which changed DNS settings and thus made PC show malicious websites instead of legitimate ones. This malicious network was dismantled in 2011 and the DNS servers were shut down. There is little chances to get infected with this malware today. There are some fake torents and pages active, but this parasite is easily detected and blocked with antivirus tools. The more risk is from the Mac version of the trojan using similar approach – RSPlug, however each of these parasites should be successfully removed with anti-virus or anti-malware scan. Automatic Malware removal tools Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , Manual removal Processes: msmsgs.exe pmsngr.exe kdqrn.exe 02.exe kdvhv.exe kdoaf.exe kdkwb.exe kdkat.exe kdlfk.exe kdefp.exe ictun.exe icthis.exe icmntr.exe isfun.exe isfmntr.exe isfmm.exe icun.exe G2-tmp.exe G5-tmp.exe sbmntr.exe sbsm.exe sbun.exe scit.exe scm.exe scu.exe uninst.exe waun.exe laf1.exe antiviirus.exe xbaqktfv.exe iebtm.exe iebtmm.exe iebtu.exe iebu.exe wcm.exe wcs.exe exqa.exe pebgkxwq.exe zfe2.exe wcu.exe vpncore.exe VideoAccessCodecInstall[1].exe Uninstall.exe nvctrl.exe Dll: dtjby.dll uimcu.dll antzozc.dll jrpkmgh.dll isfmdl.dll ictmdl.dll nczupfw.dll dfrep.dll Trojan.Zlob|eulbn.dll werbetpwg.dll sysdivx.dll vipextnog.dll werbetlrw.dll vipextgpk.dll werbettxf.dll vipextpxm.dll wowlze.dll voipwet.dll hdtip.dll fsehfcu.dll qhcvdw.dll findsiteonline.dll 1201639702.dll 1201639705.dll ofcpi.dll 1202030455.dll iinqyl.dll 1198448799.dll wamdl.dll 1198448796.dll sbmdl.dll 1202567261.dll 1202650266.dll 1203140349.dll 1204372749.dll 1203634438.dll 1203846321.dll 1204460162.dll 1204885300.dll enlfxgw.dll dkxrstqqgr.dll apdqnxp.dll btrklfr.dll 1205289674.dll bokpkov.dll altvxvm.dll drnpfdxxrs.dll| drnpfdxrqv.dll| etlrlws.dll 1205847823.dll drnpfdxsfn.dll drnpfdxlwn.dll admggxp.dll drnpfdxxsn.dll drnpfdxopx.dll drnpfdxlsk.dll drnpfdxsxp.dll kdftlboekae.dll jdxah.dll dwnrpofk.dll vbgtorfd.dll qvdntlmw.dll dcggain.dll svpekgonnof.dll svpekgonlop.dll svpekgongrk.dll drnpfdxwgv.dll ekvgsnw.dll vualf.dll qdnkewfa.dll mgsvflkw.dll rkvdr.dll temlxopqftg.dll 403445.dll 892267.dll qtvglped.dll omlbpkaw.dll dntpkwodpx.dll bubbj.dll rkaxfza.dll 814810.dll uyhjw.dll Wxdbpfvo.dll pmsoarbf.dll qnmargolbve.dll 312191.dll 561756.dll wdpoefan.dll vadokmxt.dll qdsba.dll 527631.dll wxdbpfvo.dll rtmipr.dll gndarmblvpg.dll 834668.dll qvlbodmnlks.dll gndarmblaor.dll tdomgafw.dll wetkadmr.dll qvlbodmnbof.dll 158117.dll fvowketqksn.dll fvowketqsle.dll 443059.dll qvlbodmnmle.dll 824223.dll boqnrwdmstg.dll nldfmtapndk.dll pxgdslro.dll 566828.dll 247880.dll 905757.dll 514852.dll kfcpnd.dll tusdgan.dll 162123.dll psqnuvo.dll wscmp.dll funfsnv.dll kvsdpfeafeo.dll rnopbfgt.dll xkefqtgs.dll iebr.dll iebt.dll 238044.dll wmpenv.dll sgntu.dll ibmsmyi.dll 788877.dll ksendlbtogt.dll ksendlbtqrs.dll nogxfvblqld.dll 214075.dll 851174.dll Files: msmsgs.exe isaddon.dll isamini.exe pmsngr.exe Programs\\Media-Codec\\ecodec.exe kdqrn.exe Temp\\02.exe kdvhv.exe Temp\\nsq3.tmp\\modern-header.bmp Temp\\nsq3.tmp\\nsExec.dll kdoaf.exe kdkwb.exe System\\kdkat.exe System\\kdlfk.exe System\\kdefp.exe btrklfr.dll ncompat.tlb dtjby.dll uimcu.dll %UserProfile%\\Application Data\\Microsoft\\Crypto\\RSA %UserProfile%\\Application Data\\Microsoft\\Protect dumpserv.com nvctrl.exe msmsgs.exe hp[X].tmp msvol.tlb RSA Protect vnp7s.net zxserv0.com dumpserv.com antzozc.dll ictmdl.dll isfmdl.dll nczupfw.dll icthis.exe ictun.exe isfmntr.exe isfun.exe Trojan.Zlob|eulbn.dll werbetpwg.dll sysdivx.dll vipextnog.dll werbetlrw.dll vipextgpk.dll werbettxf.dll vipextpxm.dll voipwet.dll hdtip.dll G2-tmp.exe G5-tmp.exe fsehfcu.dll qhcvdw.dll findsiteonline.dll 1201639705.dll 1201639702.dll ofcpi.dll 1202030455.dll iinqyl.dll 1198448796.dll sbmdl.dll sbmntr.exe sbsm.exe sbun.exe scit.exe scm.exe scu.exe uninst.exe wamdl.dll waun.exe 1198448799.dll laf1.exe 1202567261.dll 1202650266.dll 1203140349.dll 1204372749.dll 1203634438.dll 1203846321.dll 1204460162.dll 1204885300.dll antiviirus.exe dkxrstqqgr.dll apdqnxp.dll enlfxgw.dll 1205289674.dll altvxvm.dll bokpkov.dll drnpfdxxrs.dll drnpfdxrqv.dll etlrlws.dll drnpfdxsfn.dll 1205847823.dll drnpfdxlwn.dll admggxp.dll drnpfdxlsk.dll drnpfdxxsn.dll drnpfdxopx.dll drnpfdxsxp.dll kdftlboekae.dll jdxah.dll dwnrpofk.dll vbgtorfd.dll qvdntlmw.dll dcggain.dll drnpfdxwgv.dll svpekgonlop.dll svpekgonnof.dll svpekgongrk.dll ekvgsnw.dll vualf.dll mgsvflkw.dll qdnkewfa.dll rkvdr.dll temlxopqftg.dll 403445.dll 892267.dll qtvglped.dll omlbpkaw.dll dntpkwodpx.dll bubbj.dll rkaxfza.dll 814810.dll uyhjw.dll Wxdbpfvo.dll pmsoarbf.dll qnmargolbve.dll 312191.dll 561756.dll wdpoefan.dll vadokmxt.dll qdsba.dll 527631.dll wxdbpfvo.dll rtmipr.dll xbaqktfv.exe gndarmblvpg.dll 834668.dll qvlbodmnlks.dll gndarmblaor.dll tdomgafw.dll wetkadmr.dll qvlbodmnbof.dll 158117.dll fvowketqksn.dll fvowketqsle.dll 443059.dll qvlbodmnmle.dll 824223.dll boqnrwdmstg.dll nldfmtapndk.dll pxgdslro.dll 566828.dll 247880.dll 905757.dll 514852.dll kfcpnd.dll tusdgan.dll 162123.dll psqnuvo.dll wscmp.dll 214075 funfsnv.dll kvsdpfeafeo.dll rnopbfgt.dll xkefqtgs.dll iebr.dll iebt.dll 238044.dll iebtm.exe iebtmm.exe iebtu.exe iebu.exe wcm.exe wcs.exe exqa.exe pebgkxwq.exe zfe2.exe wcu.exe wmpenv.dll VideoAccessCodec.ocx vpncore.exe VideoAccessCodecInstall[1].exe Uninstall.exe sgntu.dll 788877.dll ibmsmyi.dll ksendlbtogt.dll ksendlbtqrs.dll nogxfvblqld.dll 214075.dll 851174.dll download.php_id=4001&a=auto Registers: HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\RegSvr32=%System%\\msmsgs.exe HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell=explorer.exe,msmsgs.exe HKCU\\Software\\Internet Security\\ HKCU\\Software\\HQvideo {DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{A3D76B96-30B9-4DCC-9B3D-D12E31280D29} {B499D34E-58EF-4927-AB9F-7AF52B2C4C82} {ab75cc7d-2751-4144-a278-5462d5a5884c} {6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{ab75cc7d-2751-4144-a278-5462d5a5884c} Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16} SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar\\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16} HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunRegSvr32=%System%msmsgs.exe HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exe HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows NT CurrentVersionWinlogonShell=explorer.exe, msmsgs.exeHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentV SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar\\{41F6170D-6AF8-4188-8D92-9DDAB3C71A78} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{60dea04c-9817-4309-bfa2-f8a1766c3cd1} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\explorer\\run Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{41F6170D-6AF8-4188-8D92-9DDAB3C71A78} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\explorer\\run\\start {41F6170D-6AF8-4188-8D92-9DDAB3C71A78} {60dea04c-9817-4309-bfa2-f8a1766c3cd1} {D579A683-0CC7-4023-BAE7-0544D0D1DA3A} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{D579A683-0CC7-4023-BAE7-0544D0D1DA3A} Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{23ED2206-856D-461A-BBCF-1C2466AC5AE3} SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{a6d478c6-7961-4fe9-be4b-e621dd640112} SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar\\{23ED2206-856D-461A-BBCF-1C2466AC5AE3} Online Add-on {23ED2206-856D-461A-BBCF-1C2466AC5AE3} {a6d478c6-7961-4fe9-be4b-e621dd640112} Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{F2BADA0D-FD61-45EF-A994-64A073FD6613} Microsoft\\Internet Explorer\\Toolbar\\{F2BADA0D-FD61-45EF-A994-64A073FD6613} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{c0ca766d-060c-48e1-b536-205e321bd174} {69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014} {c0ca766d-060c-48e1-b536-205e321bd174} {F2BADA0D-FD61-45EF-A994-64A073FD6613} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014} HKEY_CURRENT_USER\\Software\\Online Add-on {aaad3a22-1c07-45f5-bfb3-e9a8c3b382fe} {2012F73E-7427-4AD8-9E9D-6CBA6E0053D4} c7cd9e83-3bf6-47f8-b2e2-b114c96c1888 BA0BACB5-FC95-451E-94D2-4959AB0949D2 F10587E9-0E47-4CBE-84AE-7DD20B8684CC F10587E9-0E47-4CBE-ABCD-7DD20B8622FF 10C52A42-DB8B-4ade-AA4A-CED6A8282B85 7265100a-17e1-41bf-bd08-63b95a25a9c3 {27cb634d-c84e-4c00-9b53-f5523601dbad} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{27cb634d-c84e-4c00-9b53-f5523601dbad} {F10587E9-0E47-4CBE-ABCD-7DD20B862223} E404.e404mgr E404.e404mgr.1 Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F10587E9-0E47-4CBE-ABCD-7DD20B862223} NetProject {10C52A42-DB8B-4ade-AA4A-CED6A8282B67} {747e1fbe-b70f-441d-bbca-6e536c04924a} {81705D67-3F73-4983-859B-97D0922E5ABE} {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} {E85F6AA5-7A0C-49A5-9E5E-936FED62347D} {F7D09218-46D7-4D3D-9B7F-315204CD0836} {499B8A53-5949-4625-A8BF-A4D934AFC9DA} {E63648F7-3933-440E-B4F6-A8584DD7B7EB} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{10C52A42-DB8B-4ade-AA4A-CED6A8282B67} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} Microsoft\\Windows\\CurrentVersion\\Uninstall\\Internet Service Microsoft\\Windows\\CurrentVersion\\Uninstall\\MultiMedia Software Microsoft\\Windows\\CurrentVersion\\Uninstall\\Secure Browsing Microsoft\\Windows\\CurrentVersion\\Uninstall\\Web Application Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Alert Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{81705D67-3F73-4983-859B-97D0922E5ABE} Microsoft\\Internet Explorer\\Toolbar\\{81705D67-3F73-4983-859B-97D0922E5ABE} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{747e1fbe-b70f-441d-bbca-6e536c04924a} Microsoft\\Windows\\CurrentVersion\\policies\\explorer\\run\\some Microsoft\\Windows\\CurrentVersion\\policies\\explorer\\run\\start {C03FD59D-9104-44B7-929A-9EAA0BA05211} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C03FD59D-9104-44B7-929A-9EAA0BA05211} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{2C566C34-7D72-4DC1-9BBE-1121A76698F8} Microsoft\\Internet Explorer\\Toolbar\\WebBrowser Objects\\{B499D34E-58EF-4927-AB9F-7AF52B2C4C82} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{03B902B1-9B25-4173-9468-56775C85A8D4} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{8F10DE2B-E923-4548-B524-4D9C5FA80777} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{D4FEDE82-C500-4AA4-BB99-A4DAE5A65A46} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects {0D574C9F-71F9-4F3C-BA6D-CF9C0E1E3EE8} {6D7990CB-1D01-4554-9EED-75BDC6406FC2} zlob.trojan {12a31567-9883-4cc0-a684-ad5804394d69} {9E654A16-4765-4EAA-94EC-D5A6578053A4} {25E0128D-AAFC-49FF-AB11-1F12C2FCC391} {C130E860-7C1C-44F0-996C-1F995C10B61E} Security Centre Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{DC59D6DA-7CDE-4874-9F97-41C82C177069} Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler{4d51e91c-e917-4b7f-89ff-abe471e16927} Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{eb9f614b-ea44-40d0-8829-542e4f254739} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{12a31567-9883-4cc0-a684-ad5804394d69} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{38A36BC9-15D0-4EA0-ABA2-CEE104719DFF} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E4E30C12-F249-43D5-ACE3-E0C380448648} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7C109800-A5D5-438F-9640-18D17E168B88} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{db763ed8-100a-481b-8913-50a2f41dcdc3} Microsoft\\Internet Explorer\\Toolbar\\{51D81DD5-55B7-497F-95DB-D356429BB54E} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{8D0B9175-1463-4B59-80DB-4DDE662ACB2B} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{DDFF8B71-EF58-4922-ACF2-2003FE2B7481} HKEY_CLASSES_ROOT\\CLSID\\{54160F28-994B-48DD-8D83-1B2F6B9EB054} HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{54160F28-994B-48DD-8D83-1B2F6B9EB054} HKEY_CLASSES_ROOT\\CLSID\\{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Toolbar\\{F0791CA9-77CF-437E-AF92-58DCE68FA410} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7C109800-A5D5-438F-9640-18D17E168B88} HKEY_CLASSES_ROOT\\CLSID\\{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0826898D-C6EA-40BB-B636-9C82B5565312} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{413B556F-9483-4319-9DCA-5378529986E2} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} Microsoft\\Internet Explorer\\Toolbar\\{3E1A7455-8F94-40B1-A2A8-4FE1A5264F8B} Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{b0fdc513-46b9-46fc-8e70-d575ee546dae} Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{af73a174-ea1b-4f0b-b0b1-fe1486a6719c} Internet Explorer\\Toolbar\\{3E1A7455-8F94-40B1-A2A8-4FE1A5264F8B} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{F2FB4BB4-4C80-4AEE-8B59-F146B08F6193} WINDOWS\\CURRENTVERSION\\POLICIES\\EXPLORER\\RUN\\start Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{8377285E-F9CE-4DEB-936C-04CAF05F0512} {7C109800-A5D5-438F-9640-18D17E168B88} {DB9D1BB8-3615-48A6-BF50-5CB45AB28230} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{2FD21AD8-139B-4366-9390-4076D6A38201} {427B1FD8-2123-4334-A7D8-7A497363914B} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{427B1FD8-2123-4334-A7D8-7A497363914B} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{D2E5FE60-C0CB-4FC5-93D5-9736FA10A01B} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{631B47A3-474E-4850-97FB-9E7461EFC4B2} {C6D09EC9-DDB2-4EC4-9D6F-B680A7A849CF} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{40815A9A-BC7C-46D1-837D-A49ED3444F06} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C6D09EC9-DDB2-4EC4-9D6F-B680A7A849CF} {220A105A-16EE-44C1-A4C8-AD76C709FC1D} {34CF6660-9BD3-431A-BA32-6B511D4126DA} {51D81DD5-55B7-497F-95DB-D356429BB54E} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{0683b6a6-0ff9-4c6c-9240-b71ca010d48f} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{220A105A-16EE-44C1-A4C8-AD76C709FC1D} Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{B33B96B9-E0C2-4648-9819-A38DDCAFA33C} {5c7b71bb-6d49-4bdc-b60d-f9fe0481eb5f} {6B5CFD66-1F55-4FC2-B5AF-36B66E7CFE6A} {E28F671C-3D83-4149-BA2F-546A67702B49} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{6B5CFD66-1F55-4FC2-B5AF-36B66E7CFE6A} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E28F671C-3D83-4149-BA2F-546A67702B49} {9420D9C5-E151-4D83-B9A6-27DE1A7A0E5F} {99BA268B-4021-4739-9945-3C774217FE75} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{9420D9C5-E151-4D83-B9A6-27DE1A7A0E5F} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{5c7b71bb-6d49-4bdc-b60d-f9fe0481eb5f} {049e2207-f9ef-40da-91f7-8819d0c33a84} {7BC9C2E2-73A6-4FCF-B73D-CBAA20B31C9B} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7B763825-61A7-4BA0-9F7E-A77B30166346} BhoNew.BhoApp BhoNew.BhoApp.1 {257f6f44-2c64-46bb-acb4-55f9b9e0ae08} {5F920865-38C9-40DA-8FCF-D9DC83F84EC5} {95667A7A-03B3-4EE0-91AE-A4DE74D25729} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{5F920865-38C9-40DA-8FCF-D9DC83F84EC5} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{95667A7A-03B3-4EE0-91AE-A4DE74D25729} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{257f6f44-2c64-46bb-acb4-55f9b9e0ae08} {8E96D546-8096-42B2-8EBF-16AC5A119A59} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{8E96D546-8096-42B2-8EBF-16AC5A119A59} Microsoft\\Internet Explorer\\Toolbar\\{3F5A62E2-51F2-11D3-A075-CC7364CAE42A} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{99BA268B-4021-4739-9945-3C774217FE75} Web Technologies {0065DF2C-B98B-4CEE-B716-19B99F7D4780} {3A4CDC69-BB0A-4766-8826-8EE676F51885} {4CD7CDF7-C7B8-4DE0-972E-0B1357A1855C} {5832653A-348F-4CFF-9F8F-063E2AFB19CF} {7B763825-61A7-4BA0-9F7E-A77B30166346} {BA8EFD75-A3AC-42FC-BD2C-3C92653DA2D7} {F5AC7B48-0B15-48CC-A3BF-4EAFD4EBC7E4} {06D96CD0-379B-406C-9968-892CDAAE1893} {B146C078-8A8C-46C2-8D99-29BF9AB78A43} {8B7D389D-9438-44AF-923A-91C36BCD5FD0} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{A49E097A-D6EF-4B2F-8B0F-1230E998587F} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{C0F371D7-926D-4700-B65E-63BFF1197205} Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEBrowse Tool Microsoft\\Windows\\CurrentVersion\\Uninstall\\IExplorer Bar Microsoft\\Windows\\CurrentVersion\\Uninstall\\Warning Center Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\{F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar\\{F99D0 {85BDD81D-31FD-4A6B-A73C-3955B128D2EC} {A49E097A-D6EF-4B2F-8B0F-1230E998587F} {B8301AF7-D00E-4EA4-87C1-5FF4644FBBA1} {C0F371D7-926D-4700-B65E-63BFF1197205} {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} Microsoft\\Internet Explorer\\Toolbar\\{85BDD81D-31FD-4A6B-A73C-3955B128D2EC} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{7BC9C2E2-73A6-4FCF-B73D-CBAA20B31C9B} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{B8301AF7-D00E-4EA4-87C1-5FF4644FBBA1} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{049e2207-f9ef-40da-91f7-8819d0c33a84} Microsoft\\Internet Explorer\\Toolbar\\{F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{10D84632-BD4D-4955-86A4-150EE134E5DE} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{257f6f44-2c64-46bb-acb4-55f9b9e0ae08} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{80C0F2F5-68A6-428A-8625-8A22E0CDD699} Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{CC021A21-6AC0-4BDA-A503-68F041A7EAD2} Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler\\{99f8405b-63d1-421a-83bb-7b4b0642ac28} Zlob facts Type: Trojan Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , TOC 2 responses to “Zlob” do the zlob control your keyboard?my key board does not work and mu pc have the w32 myzor how cn i fix it if i cant use my key board? Pingback: Trojan.DNSChanger - how to remove Leave a ReplyYour email address will not be published. Required fields are marked *Comment * Name * Email * Website
do the zlob control your keyboard?my key board does not work and mu pc have the w32 myzor how cn i fix it if i cant use my key board?