Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 2 December 2005 16:29:36 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/QQPass-AM is a Trojan for the Windows platform with keylogging functionality.
When first run Troj/QQPass-AM copies itself to:
<Windows temp folder>\temp~2
<Windows system folder>\algesetp.exe
and creates the following files:
<Windows system folder>\temp.jpg
<Windows system folder>\windky.dll
The files temp.jpg and windky.dll are clean and can be simply deleted.
The following registry entry is created to run algesetp.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SystUphes
<Windows system folder>\algesetp.exe
Troj/QQPass-AM may attempt to terminate several processes and services related to anti-virus and security programs.
