Sophos

Troj/Bckdr-QMR

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 28 March 2008 02:14:35 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bckdr-QMR is a Trojan for the Windows platform.

When run Troj/Bckdr-QMR creates the files:

<System>\6to4.dll- also detected as Troj/Bckdr-QMR
<System>\6to4.sys- also detected as Troj/Bckdr-QMR

Troj/Bckdr-QMR registers the DLL as a Windows service with the display name "6to4" so that the Trojan is run on startup. Registry entries are set under:

HKLM\SYSTEM\CurrentControlSet\Services\6to4

Troj/Bckdr-QMR may also attempt to set the following registry entry:

HKLM\SYSTEM\CurrentControlSet\Services\Beep\Enum
INITSTARTFAILED
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer