Troj/Agent-ZMO
Posted: January 3, 2013
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Ranking: | 2,277 |
|---|---|
| Threat Level: | 9/10 |
| Infected PCs: | 302 |
| First Seen: | January 3, 2013 |
|---|---|
| Last Seen: | March 7, 2025 |
| OS(es) Affected: | Windows |
Troj/Agent-ZMO is a Trojan that's distributed through spam e-mail messages. Current Troj/Agent-ZMO attacks utilize message formats that portray Troj/Agent-ZMO as a series of bikini photos from an acquaintance, although enclosed file actually is a malicious SCR (screensaver type executable). Executable files that are downloaded from misleading and deceptive sources – including both EXE and SCR file types – are one of the leading methods through which malware can be introduced to new computers. Due to Troj/Agent-ZMO's lack of symptoms and high probability of conducting heavily invasive attacks against any computer that Troj/Agent-ZMO gains access to, SpywareRemove.com malware researchers recommend removing Troj/Agent-ZMO both immediately and with a worthy anti-malware product.
Troj/Agent-ZMO: Digital Attacks Hiding Behind Swimsuits
SpywareRemove.com malware research team has seen cases of Troj/Agent-ZMO being marketed to multiple countries and in multiple languages, such as English and Eurocentric languages like Italian. Although the spam e-mail messages that carry Troj/Agent-ZMO attacks appear to be casting wide nets for victims, their ruse always is the same: they pretend to offer season's greetings along with a ZIP archive of scantily-clad women. These e-mails often use formats that try to pass themselves off as being sent by a friend named Gretchen, Selma, Ciara, etc.
The attachment of a normal ZIP file that includes the actual malicious file, Troj/Agent-ZMO, is a typical tactic for spam-based malware distribution. SpywareRemove.com malware experts note that this is one of many good reasons to be exceptionally careful about opening ZIP archives from unusual sources. Similar e-mail-based malware attacks that also have been recorded this year include Win32/Cbeplay.P, Troj/Bredo-VV, Trojan-Spy.Win32.Zbot.gtvm, TSPY_ZBOT.SMHA and Troj/Agent-WXL – some of which even use the same basic hoax as Troj/Agent-ZMO: the promise of supposedly enticing feminine photos.
What Happens to Your Computer After You Get an Eyeful of Troj/Agent-ZMO
SpywareRemove.com malware analysts have noted that Troj/Agent-ZMO does not have any visible symptoms during its immediate attacks, but, in spite of its low-key attitude, Troj/Agent-ZMO is a meaningful danger to your computer's security. Designed to compromise Windows PCs, Troj/Agent-ZMO may conduct any of the following attacks:
- Install other malicious software without your permission, such as rogue security programs, ransomware Trojans or browser hijackers.
- Change your security settings to disable network and/or browser-related security features.
- Be used in attacks that try to steal confidential information. Account passwords and login fields are especially targeted by such attacks, which can include keylogging (attacks that record all the information that you type on your keyboard).
- Block other programs, particularly Windows security tools like Task Manager, to prevent you from removing other malware or even Troj/Agent-ZMO, itself.
Like all spam-based attacks, you should scan your PC with a dependable anti-malware program as soon as possible after your PC has been compromised by the Troj/Agent-ZMO file attachment. Doing so will prevent Troj/Agent-ZMO from causing permanent damage to your PC or its contents, but delay risks additional complications in the form of other PC threats being installed.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:6ec7654c71ea3e44339c2fdb40000925
File name: 6ec7654c71ea3e44339c2fdb40000925Size: 276.48 KB (276480 bytes)
MD5: 6ec7654c71ea3e44339c2fdb40000925
Detection count: 35
Group: Malware file
Last Updated: January 7, 2013
Bikini.zip
File name: Bikini.zipMime Type: unknown/zip
Group: Malware file
Bikini.scr
File name: Bikini.scrMime Type: unknown/scr
Group: Malware file
Additional Information
| # | Message |
|---|---|
| 1 | Subject: HAPPY NEW YEAR Ciao mia cara! Come stai? Come promesso, ecco le mie foto bikini. Spero che sarà love it! Questo è il mio umile dono per il nuovo anno! Ci vediamo più tardi :) Il tuo amore Selma 01.01.2013 16:04:43 |
| 2 | Subject: Merry Christmas Hello my dear!!! How are you? As I promised, here's my bikini photos. I hope you will be love it! This is my humble gift for Christmas! See you later :) Your love Ciara 28.12.2012 |
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.