|
||
7/28: Downloader-NE.dr a New Trojan Downloader-NE.dr is a downloader dropper trojan packed with FSG and injects a DLL component in to the memory space of the Explorer.exe process.
When executed it drops a copy of itself into the %Sysdir% folder as ECT.EXE. For example: C:\Winnt\System32\ECT.EXE
It also drops a DLL file (ERL.EXE) into the same folder. This DLL file is 5,632 bytes in size. This DLL file is injected into the shell process of EXPLORER.EXE.
The following registry keys are created:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ This trojan will attempt to download and run a script from a Russian web site.
More information is at McAfee page.
|
||
|