Sophos

Troj/QQPass-AIX

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 9 October 2006 14:06:57 (GMT)
Last updated 30 March 2007 07:33:11 (GMT)
Detected by All Sophos products

Action

More Information

Troj/QQPass-AIX is a password stealing Trojan for the Windows platform.

Troj/QQPass-AIX includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/QQPass-AIX is installed the following files are created:

<Temp>\alkdoieulskjdf
<System>\GDIPLUS32.dll

Both of these files are also detected as Troj/QQPass-AIX.

The file GDIPLUS32.dll is registered as a layered service provider (LSP), creating and modifying registry entries in the Winsock 2 system configuration database under:

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\

Note: the LSP chain should only be repaired by experienced individuals or under expert guidance.

Troj/QQPass-AIX may also create the file <Program Files>\Internet Explorer\plugins\Recycled.sys, which may be registered as a COM object and ShellExecute hook.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer