Home / malwarePDF  

Trojan.Retefe


First posted on 26 July 2014.
Source: Symantec

Aliases :

There are no other names known for Trojan.Retefe.

Explanation :

Once executed, the Trojan copies itself to the following location:
%AllUsersProfile%\Documents\[RANDOM CHARACTERS FILE NAME].exe

The Trojan adds a root certificate under the following registry subkey:
HKEY_CURRENT_USERS\Software\Microsoft\SystemCertificates\Root\Certificates

The Trojan may then steal information from the compromised computer.

Last update 26 July 2014

 

TOP