Thursday, September 07, 2006

Trojan utilizes Encrypting File System (EFS) to Protect Itself

Recently a trojan was seen to take advantage of EFS to protect itself and execute with administrative privileges. The trojan creates an administrator login account with a random name and random password. Using this login key pair it then encrypts the downloader component that it drops. It then creates a service that points to the encrypted file.

read more | digg story filed under , ,

Sphere: Related Content