Troj/Bckdr-QIL drops the files:
<Windows>\iasrecst.exe
<Windows>\drmclient32.dll
and creates a registry entries
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Keyboard Enhance 2.0.
iasrecst.exe
Troj/Bckdr-QIL contains functionality to download and run additional malware.
T
When run Troj/Bckdr-QIL injects and runs drmclient32.dll is in the process space of Internet Explorer. The dropped dynamically loaded library component monitors and restarts iasrecst.exe if it is terminated.
Troj/Bckdr-QIL contains backdoor functionality that allows a remote attacker to take control of the infected computer.