TROJAN.JORIK.DREFIR.BF
Name:
Trojan.Jorik.Drefir.bf
Added:
August 29, 2011
Type:
Trojan
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Description:
When Trojan.Jorik.Drefir.bf is executed, it performs the following activities:After execution it drops the following files:%Appdata%\cmd.exe%Appdata%\cmd.exec%Appdata%\{Random Number}.exeIt creates/modifies the following registry entries:UACDisableNotify = 0x00000000HKLM\SOFTWARE\Microsoft\Security CenterEnableLUA = 0x00000000HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system{cmd.exe} = "%Appdata%\cmd.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunSystemReq = "%Appdata%\{Random Number}.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run{cmd.exe} = "%Appdata%\cmd.exe"HKU\Software\Microsoft\Windows\CurrentVersion\Runcmd.exe runs every time Windows startsSystemReq = "%Appdata%\{Random Number}.exe"HKU\Software\Microsoft\Windows\CurrentVersion\Run
Malware problems?We can help.
Evaluate Thirtyseven4 Antivirus Now
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4