The virus Zlob.gen has a lot of variants, we are not going to explain each particularity off all his variants but we will show you only section you have to know.
This worm try to communicate with one of this adresses http://nx.51ylb.cn/soft, securitypills.com, http://33.xingaide8.cn, gateow.com, www.gatecb.com and try to download files to the local disk.
This virus change too Internet Explorer's paramters.
Some variants :
- Trojan.DL.Zlob.Gen.34 [PCTools]
- Trojan-Downloader.Zlob.GEN [PCTools]
- Trojan.DL.Zlob.Gen!Pac.45 [PCTools]
- New Poly Win32 [McAfee]
- New Malware.aj [McAfee]
- Puper [McAfee]
- TROJ_ZLOB.TH [Trend Micro]
- WORM_NUCRYPT.GEN [Trend Micro]
|