Home Malware Programs Trojans Trojan.Win32.Jorik.Fraud.un

Trojan.Win32.Jorik.Fraud.un

Posted: August 16, 2011

Trojan.Win32.Jorik.Fraud.un is a Trojan that spreads via existing network vulnerabilities or security exploits. Trojan.Win32.Jorik.Fraud.un runs in the background and slows down your computer system by taking over a large amount of system resources. Trojan.Win32.Jorik.Fraud.un creates its startup registry entry so that it could run every time you start Windows. Trojan.Win32.Jorik.Fraud.un enables attackers gain remote access to the affected computer system. Trojan.Win32.Jorik.Fraud.un can steal and transmit personal information to remote attackers for illegitimate purposes. Remove Trojan.Win32.Jorik.Fraud.un as quickly as possible once you detect it.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CommonAppData%\XPosROXaNo.exe File name: %CommonAppData%\XPosROXaNo.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] SaveZoneInformation = 0x00000001[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr = 0x00000001[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] XPosROXaNo = "%CommonAppData%\XPosROXaNo.exe"[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] CheckExeSignatures =[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr = 0x00000001[HKEY_CURRENT_USER\Software] 75fa38b7-8b94-4995-ad32-52e938867954 = ""[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] LowRiskFileTypes = "/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:"
Loading...