Home Malware Programs Trojans JAVA_DLOAD.ZZC

JAVA_DLOAD.ZZC

Posted: January 11, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 82
First Seen: January 13, 2012
OS(es) Affected: Windows

JAVA_DLOAD.ZZC is a malicious applet that uses JavaScript-based exploits to attack computers by gathering personal information for future remote attacks. Although JAVA_DLOAD.ZZC isn't affiliated with any currently-known types of activist organizations, recent hacking attacks against a variety of human rights websites have inserted JAVA_DLOAD.ZZC into their websites. If you've visited a human rights or activist site that has been reported to be attacked by JAVA_DLOAD.ZZC-promoting hackers, SpywareRemove.com malware researchers advise you to scan your PC with anti-malware software to make sure that your computer hasn't become JAVA_DLOAD.ZZC's most recent victim. Since JAVA_DLOAD.ZZC, like backdoor Trojans, can grant criminals a limited amount of access to your PC and control over it, you should consider any possibility of a JAVA_DLOAD.ZZCinfection to be a high-level threat, even though JAVA_DLOAD.ZZC's distribution numbers are currently-low.

JAVA_DLOAD.ZZC – Just a Drop-In for Anti-Activist Spies

As malicious Java content, JAVA_DLOAD.ZZC is capable of attacking any PC that can use Java, although JAVA_DLOAD.ZZC is specific to Java Runtime Environment versions 7 and 6, from Update 27 (and previous versions). The vulnerability that JAVA_DLOAD.ZZC exploits, CVE-2011-3544, allows JAVA_DLOAD.ZZC to drop other types of malicious files on your PC. These files, in turn, are involved in compromising your computer's security and will gather information about your PC to send off to criminals. Since JAVA_DLOAD.ZZC's payload can be considered equivalent to a backdoor Trojan and may be used to steal personal information, SpywareRemove.com malware experts recommend the total annihilation of JAVA_DLOAD.ZZC and related PC threats as soon as you have an anti-malware program that's up to the job.

JAVA_DLOAD.ZZC is distributed, entirely by accident, by the home sites of a variety of human rights organizations. These sites are attacked by independent hackers who insert JAVA_DLOAD.ZZC into the website and cause JAVA_DLOAD.ZZC to be automatically-downloaded onto the computers of visitors. Caution when visiting such sites is extremely-advisable – at least until recent JAVA_DLOAD.ZZC attacks have been put to a halt. Of particular note is the fact that the server that JAVA_DLOAD.ZZC uses as a part of its attack also contains files that are indicative of additional attacks against many types of similar websites, and JAVA_DLOAD.ZZC's hackers don't appear to have plans to stop their website attacks any time soon.

Preserving Your Own Rights from JAVA_DLOAD.ZZC's Violation

SpywareRemove.com malware analysts recommend avoiding likely-to-be-targeted websites as an easy way to stay away from prospective JAVA_DLOAD.ZZC attacks. Nonetheless, if this is impossible or undesirable, there are other methods to keep JAVA_DLOAD.ZZC out of your PC:

  • Refusing to install Java, without which JAVA_DLOAD.ZZC will be unable to function.
  • Disabling Java for websites that you deem to be high-risk. The majority of browsers include such options in their default security settings.
  • Keeping Java up-to-date to patch out the CVE-2011-3544 vulnerability that JAVA_DLOAD.ZZC uses to attack your PC.

If all of these solutions fail to keep JAVA_DLOAD.ZZC off of your computer, SpywareRemove.com malware experts don't recommend deleting JAVA_DLOAD.ZZC or files that JAVA_DLOAD.ZZC dropped by yourself. This is very-likely to fail to remove all components of a JAVA_DLOAD.ZZC infection, which is best-deleted by dedicated anti-malware software.

Technical Details

Additional Information

The following URL's were detected:
new-workfromhome.com
Loading...