Overview
Date Discovered | 6-Jul-12 12:07:00 |
Added DAT Info | 9.142.7000 |
Threat assesment | Low |
Virus Type | Trojan |
Affected OS | Windows Vista Windows XP Windows 2003 Server Windows 2000 |
Length | 49664 |
Aliases | Trojan.Win32.Jorik.Androm.ni (AVP) |
Technical Information
- Copies itself as svchost.exe in the %Documents and Settings%\All Users folder
- Adds the value
SunJavaUpdateSched = %Documents and Settings%\All Users\svchost.exe
under the key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
in the Windows registry to hook system startup.
- This trojan attempts to download malicious files on the victim machine.
Removal Procedure
- Update the product to the latest version.
- Restart the system in safe mode.
- Run a full system scan.
- Delete all the files detected as infected with this virus.
- Open the Windows Registry Editor.
- Delete the value
SunJavaUpdateSched = %Documents and Settings%\All Users\svchost.exe
under the key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Close the Windows Registry Editor.
- Restart the system.