Troj/VanBot-BQ is a downloader Trojan which will download, install and run new software without notification that it is doing so.
Troj/VanBot-BQ is a downloader Trojan which will download, install and run new software without notification that it is doing so.
When first run Troj/VanBot-BQ copies itself to:
<Startup>\taskman.exe
<System>\acroup32.exe
The following registry entries are created to run acroup32.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Acrobat Read
<System>\acroup32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Acrobat Read
<System>\acroup32.exe