Home Malware Programs Trojans Trojan.Win32.Jorik.Diodih.z

Trojan.Win32.Jorik.Diodih.z

Posted: July 11, 2011

Trojan.Win32.Jorik.Diodih.z is a Trojan that's distributed with pirated applications and hides itself by using the same name as native Windows files. Attacks from Trojan.Win32.Jorik.Diodih.z often result in lessened network security due to opened ports, which can be an initial step in allowing remote attackers to control your PC or in installing other computer threats. Obvious indications of a Trojan.Win32.Jorik.Diodih.z infection can be limited, but the potential damage that Trojan.Win32.Jorik.Diodih.z's actions can cause require that you remove Trojan.Win32.Jorik.Diodih.z with a trusted anti-malware program as soon as you have a chance to do so.

How You Can Keep Trojan.Win32.Jorik.Diodih.z from Grubbing Up Your Network Security

Trojan.Win32.Jorik.Diodih.z has a relatively large list of aliases, although detecting Trojan.Win32.Jorik.Diodih.z by a different name doesn't indicate a different type of Trojan.Win32.Jorik.Diodih.z infection. Some of Trojan.Win32.Jorik.Diodih.z's many alternate titles include TR/Jorik.Diodih.z.5, VirTool:MSIL/Injector.gen!B, Win32:Dropper-gen, Trojan.Generic.5845557, MSIL/Injector.EM Trojan, Mal/Generic-L, Generic22.ACXV and VirTool.MSIL.

Regardless of which name you find Trojan.Win32.Jorik.Diodih.z using, Trojan.Win32.Jorik.Diodih.z's presence is a serious security threat. Current infection paths for Trojan.Win32.Jorik.Diodih.z include P2P networks and pirated software. With respect to the latter, although the program itself may function properly, Trojan.Win32.Jorik.Diodih.z may be bundled with it and infect your PC in secret while you're paying attention to the visible installation process.

All known Trojan.Win32.Jorik.Diodih.z infections have been reported in 2011, and anti-virus software that's equipped with excessively old virus definition databases may be unable to delete Trojan.Win32.Jorik.Diodih.z. Keep your security software updated on a regular basis, and you'll suffer less risk of being harmed by a Trojan.Win32.Jorik.Diodih.z infection.

Trojan.Win32.Jorik.Diodih.z: the Invisible Security Killer

Although Trojan.Win32.Jorik.Diodih.z's behavior may vary from one infection instance to another one there are common traits that all known Trojan.Win32.Jorik.Diodih.z attacks have shared with each other:

  • Trojan.Win32.Jorik.Diodih.z will cement its position on your PC with multiple files that should all be considered variants of Trojan.Win32.Jorik.Diodih.z. In most cases, if your anti-virus software only detects a single Trojan.Win32.Jorik.Diodih.z file after a full scan, your software may have missed another part of the Trojan.Win32.Jorik.Diodih.z infection.
  • Despite Win32.Jorik.Diodih.z's high likelihood of being active on a constant basis, Trojan.Win32.Jorik.Diodih.z may not be visible due to hiding Win32.Jorik.Diodih.z's files with the name 'ctfmon.exe.' The natural ctfmon.exe file is a native part of Windows, but Trojan.Win32.Jorik.Diodih.z uses the same name to avoid being seen. Be suspicious if you notice multiple ctfmon.exe files running in your Task Manager.
  • All Trojan.Win32.Jorik.Diodih.z infections have also been seen to open network ports. This attack can be used for multiple purposes, including allowing Trojan.Win32.Jorik.Diodih.z to download and install other malicious programs, letting distant hackers control your PC or allowing Trojan.Win32.Jorik.Diodih.z to transmit private information to criminals.

Ultimately, although the signs of Trojan.Win32.Jorik.Diodih.z's attacks are limited, the possible damage can be severe, and you shouldn't tarry in removing Trojan.Win32.Jorik.Diodih.z from your PC with the best anti-virus program that you can find.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\ctfmon.exe
    2 %Temp%\IXP000.TMP\1.exe
    3 %Temp%\IXP000.TMP\ppi.exe
    4 %Temp%\IXP001.TMP\1.exe
    5 %Temp%\IXP001.TMP\ppi.exe
    6 %Temp%\IXP002.TMP\1.exe
    7 %Temp%\IXP002.TMP\ppi.exe
Loading...