Home / malwarePDF  

Trojan.Zlob.CKZ


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Trojan.Zlob.CKZ is also known as Trojan-Downloader.Win32.Zlob.nwr Win32/TrojanDownloader.Zlo.

Explanation :

At execution the trojan access the following webpage:

http://69.50.164.54/this/[removed]/stereo/music.php,
using "internetsecurity" as UserAgent.

Then downloads and executes the file:

http://dl1.virusheat.com/downloads/[removed]/vrh_setup.exe

which installs a rogue antivirus and display fake security alerts or notifications
to trick user to buy the paid version of VirusHeat

Last update 21 November 2011

 

TOP