JAVA_DLOADER.NZT
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may arrive bundled with malware packages as a malware component.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. As of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
Arrival Details
This Trojan may arrive bundled with malware packages as a malware component.
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}box.com/u/68019757/a.gif
It saves the files it downloads using the following names:
- {all user's profile}\{8 random characters}.exe
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
As of this writing, the said sites are inaccessible.
NOTES:
It also downloads the file from the URL specified in the parameter l.