Sophos

Troj/Laqma-A

Aliases
  • Trojan-Downloader.Win32.Agent.bsh
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 27 July 2007 06:06:14 (GMT)
Last updated 27 July 2007 06:30:33 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Laqma-A is a Trojan for the Windows platform.

When first run Troj/Laqma-A may copy itself to some of the following locations:

<System>\qm<random characters>exe
<System>\lanmanwrk.exe

When first run Troj/Laqma-A also creates the following files:

<System>\iexchg.dll
<System>\lanmandrv.sys
<System>\qmopt.dll
<System>\<current filename>.jpg

The file lanmandrv.sys is also detected as Troj/Laqma-A, and is used to provide stealthing for the Trojan. The other files may be safely deleted.

The file lanmandrv.sys is registered as a new system driver service named "lanmandrv", with a display name of "lanmandrv". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv

Troj/Laqma-A may attempt to delete the following registry in order to prevent a file from running on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ZwQueryService

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer