Troj/Nofere-A is a Trojan for the Windows platform.
Troj/Nofere-A includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Nofere-A may download and execute files from remote locations, delete registry entries and kill specified processes.
When first run Troj/Nofere-A copies itself to C:\Progra~1\Eset\iexpl0re.exe.
Troj/Nofere-A may also copy itself to the Windows, Windows system or Temp folders.
The following registry entry is created to run iexpl0re.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ravshell
<Program Files>\Eset\iexpl0re.exe
Troj/Nofere-A may set a registry entries under the following location:
HKCR\ferefile