Troj/Bckdr-PQN is a backdoor Trojan for the Windows platform.
When first run Troj/Bckdr-PQN copies itself to <System>\pgql.exe.
The following registry entry is created to run pgql.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
PGQL
<System>\pgql.exe
Troj/Bckdr-PQN includes functionality to:
- act as a proxy redirecting internet traffic
- download code from the internet and run them