Additional Details
This trojan uses Shockwave Flash Object (SWFObject) Java Script to view the following crafted SWF content on the browser page:
• http://jzm015.cn/[Removed]115.swf
• http://jzm015.cn/[Removed]64.swf
• http://jzm015.cn/[Removed]47.swf
• http://jzm015.cn/[Removed]45.swf
• http://jzm015.cn/[Removed]28.swf
• http://jzm015.cn/[Removed]16.swf
All of the listed SWF files are detected as Exploit.SWF.Downloader.eh.
The purpose of the malicious flash file is to download additional malware.