Antivirus and Security Software from Sophos

Sophos blogs

Troj/Rasdoor-A

Aliases
  • Trojan.Win32.Dialer.gq
  • W32/Qdialer.FZ
  • BackDoor-CMS
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 4 August 2005 17:36:13 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Rasdoor-A is a backdoor Trojan for the Windows platform.

When first run Troj/Rasdoor-A copies itself to dc.exe and creates the file backdoor.log, both in the current user's temporary folder.

The following registry entry is created to run dc.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BD
<path to copy of Trojan in temporary folder>

Troj/Rasdoor-A connects to a TCP port on a remote computer. An attacker listening on this port can send commands through this connection, causing the infected computer to:

execute arbitrary commands
list processes and files
transfer and delete files
kill processes

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer