When Troj/Bckdr-QVN is first run the following files are created:
<System>\lowsec\user.ds - zero byte file
<System>\lowsec\local.ds - zero byte file
<System>\lowsec\user.ds.lll - data file
<System>\sdra64.exe - copy of Troj/Bckdr-QVN
The following registry entry is set to start Troj/Bckdr-QVN automatically on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\sdra64.exe