Friday, March 20, 2009

stabilityinetscan: Zlkon Malware Drop Fake AV - Rogueware browser hijacker - Zlkon Malware Drop

Another site which promote "Internet Antivirus Pro" a rogue application also
called SystemSecurity or WinWebSecurity.

The FAKE scanner display fake alerts stating that you are infected with
Admess trojan (tcpservice.exe), zserv.Transponder.Trojan (ZServ.dll)
and some other malware.

Site screenshot:

Template 1: Screenshot Screenshot Pop Up Message

Template 2:

Fake messages:

Windows Security Center
Virus (I-Worm.Trojan.b) was found on your computer!
Click 'OK' to install System Security Antivirus.

Windows Security Center recommends you to install System Security Antivirus.

Fake Windows Security Center:

Security Essentials: To help protect your computer, make sure the four security
essentials below are marked On or OK

- Firewall is set to "On"
- Automatic updating is set to "Not automatic"
- Malware protection and "Other Security Settings" are set to "Check Settings" - Windows Security Center: Security essentials - Windows Security Center: Security essentials


 Site URLs: 
 Response Headers 
 (Status-Line):HTTP/1.1 200 OK
Date:Fri, 20 Mar 2009 xx:xx:xx GMT
Cache-Control:public, must-revalidate
Content-Disposition:attachment; filename="install.exe"
Keep-Alive:timeout=1, max=100
 File info:install.exe 
 File size57894 bytes 
 First received03.20.2009 08:33:18 (CET) 
 Results26/39 (66.67%) 
 PE Info( base data )
entrypointaddress.: 0x28230
timedatestamp.....: 0x49bf47e1 (Tue Mar 17 06:49:05 2009)
machinetype.......: 0x14c (I386)

Result when running: - InternetAntivirusPro

HTTP Request: []


 File info:SystemSecurity.exe 
 File size2206720 bytes 
 VirusTotal:First Report 
 First received03.18.2009 02:31:35 (CET) 
 ResultsResult: 16/39 (41.03%) 
 Second time03.20.2009 08:51:04 (CET) 
 Results22/39 (56.42%) 
 New infoPrevx 

Application screenshot:
 SystemSecurity - WinWebSecurity: Application Screenshot
Domain sharing IP with
We can see more domain previously served for malware drop with robtex graph Robtex graph for - Zlkon Malware Drop