Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: The End of Zlob  (Read 3111 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
The End of Zlob
« on: February 06, 2009, 08:20:35 AM »
Sounds good but reading the article is sort of alarming. We haven't seen the worst malware yet.

Quote
The Zlob Trojan, which was the one of the most, if not the most, active Trojan displaying advertisements and installing Rogue anti-spyware programs, is no longer under development. This Trojan was responsible for promoting and installing rogue anti-spyware programs onto millions of computers. In a a message found encoded in one of their Trojans, we learn that the Zlob author is closing down shop and moving on to other malware projects such as shellcodes and rootkits. Though this is good in terms of rogue programs, it does not bode well for future malware that we will see coming from this, unfortunately, talented programmer.

In October Microsoft wrote about discovering an encoded message in the Zlob Trojan directed towards them by the malware author. This message stated:

    I want to see your eyes the man from Windows Defender's team

Recently a group of French malware & security analysts have analyzed a newer variant of the Zlob Trojan and found another message encoded in the file. This message contains a farewell message from the author and information about the projects he will be involved with in the future.

    For Windows Defender's Team: I saw your post in the blog (10-Oct-2008) about my previous message. Just want to say 'Hello' from Russia. You are really good guys. It was a surprise for me that Microsoft can respond on threats so fast. I can't sign here now (he-he, sorry), how it was some years ago for more seriously vulnerability for all Windows ;) Happy New Year, guys, and good luck! P.S. BTW, we are closing soon. Not because of your work. :-)) So, you will not see some of my great ;) ideas in that family of software. Try to search in exploits/shellcodes and rootkits. Also, it is funny (probably for you), but Microsoft offered me a job to help improve some of Vista's protection. It's not interesting for me, just a life's irony.

Over the years, I have had extensive experience with rogue anti-spyware programs, and I can tell you that Zlob was one of the first Trojans of its kind. It used techniques for displaying ads and fake alerts that at the time were unheard of, and though they were not always the most difficult to remove, they were so aggressive in pushing out new versions that it was hard to keep track of them. For example, the rogue called SpywareQuake, in a 2 month period, had over 50 different variants of Zlob advertising it. Below I have included a list, in chronological order, of most of the Rogue anti-spyware programs that were promoted via the Zlob Trojan.

Talented guy. Too bad he's a crook. Full story: http://www.bleepingcomputer.com/forums/topic197269.html

reddevilggg



    Expert

    Thanked: 69
  • Experience: Beginner
  • OS: Windows 7
Re: The End of Zlob
« Reply #1 on: February 06, 2009, 09:28:55 AM »

Be Pure
Be Vigilant
Behave
11 cheers for binary !

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: The End of Zlob
« Reply #2 on: February 06, 2009, 09:24:46 PM »
If a guy like this moves to rootkits, I'm gonna shut my computer down right now ;D