Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | September 2007 (4.21) |
| Protection available since | 27 July 2007 06:06:14 (GMT) |
| Last updated | 27 July 2007 06:30:33 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Laqma-A is a Trojan for the Windows platform.
When first run Troj/Laqma-A may copy itself to some of the following locations:
<System>\qm<random characters>exe
<System>\lanmanwrk.exe
When first run Troj/Laqma-A also creates the following files:
<System>\iexchg.dll
<System>\lanmandrv.sys
<System>\qmopt.dll
<System>\<current filename>.jpg
The file lanmandrv.sys is also detected as Troj/Laqma-A, and is used to provide stealthing for the Trojan. The other files may be safely deleted.
The file lanmandrv.sys is registered as a new system driver service named "lanmandrv", with a display name of "lanmandrv". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv
Troj/Laqma-A may attempt to delete the following registry in order to prevent a file from running on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ZwQueryService
