Sophos

Sophos blogs

Troj/Agent-BQ

Aliases
  • W32/RAHack
  • BKDR_RASBA.B
  • Backdoor.Win32.Agent.go
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 January 2005 08:47:37 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Agent-BQ is a Windows Trojan which attempts to copy a file svchsot.exe to the Windows system folder and run it.

The Trojan copies itself to the Windows system folder and prepends the following registry entry with itself, changing the registry entry from:

HKCR\exefile\shell\open\command
@
"%1" %*

to

HKCR\exefile\shell\open\command
@
<filename> "%1" %*"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer