Sophos

Troj/QQPass-CI

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 January 2006 02:40:18 (GMT)
Last updated 24 October 2006 00:56:23 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/QQPass-CI is a Trojan for the Windows platform.

Troj/QQPass-CI may send collected information to a remote user via email. The Trojan contains functionality to terminate the anti-virus and security related processes.

When first run Troj/QQPass-CI copies itself to:

<Temp>\temp~3
<System>\agetlktsyr.exe

and creates the file <System>\temp1.jpg.

The file temp1.jpg is clean and can be safely removed.

The following registry entry is created to run agetlktsyr.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavUpteni
<System>\agetlktsyr.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer