October 24, 2012
The fake messages have the subject "Order N" (with “N” being a random number) and incorporate the following text:
You can download your Microsoft Windows License here.
Trojan.Necurs.97 is capable of self-replication and infects removable drives and shared network resources. When launched, the Trojan horse creates an executable file and makes changes to the Windows registry so that the file is launched at Windows startup. Then the Trojan searches the memory for running processes of Internet Explorer and Mozilla Firefox, and if successful, attempts to inject its code into them. After that Trojan.Necurs.97 attempts to copy itself to all available removable drives as a file with a random name, and creates an autorun.inf file in the drive's root folder to be launched automatically every time the device is plugged into a computer.
Trojan.Necurs.97 connects to remote servers controlled by attackers, reports its successful installation in the infected system, and waits for commands which include commands to download different applications to the compromised system and transfer files from the system to a remote host.
Doctor Web advises users to be careful and refrain from clicking on links in emails from unknown senders.
Tell us what you think
To ask Doctor Web’s site administration about a news item, enter @admin at the beginning of your comment. If your question is for the author of one of the comments, put @ before their names.