TROJ_JORIK.ECC
VirTool:Win32/DelfInject.gen!X (Microsoft); Trojan.Win32.Jorik.Vobfus.gldy (Kaspersky); Trojan.Win32.Generic!BT (Sunbelt); Trojan horse Generic31.AJTV (AVG)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
![](/vinfo/imgFiles/legend.jpg)
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}oseu.dominiotemporario.com/fugi/Instal.teaz
It saves the files it downloads using the following names:
- All Users' %User Startup%\Instal.teaz
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}oseu.{BLOCKED}otemporario.com/fugi/Instal.xml
However, as of this writing, the said sites are inaccessible.