Sophos

Troj/Vaq-A

Aliases
  • Trojan-PSW.Win32.Lmir.agp
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 July 2005 20:42:33 (GMT)
Last updated 27 March 2006 04:43:04 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Vaq-A is a Trojan downloader for the Windows platform.

When first run Troj/Vaq-A copies itself to:

<Windows system folder>\rundIl32.exe
<Windows system folder>\¡¡NOTEPAD.EXE

The following registry entry is created to run rundIl32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe rundIl32.exe

The following registry entry is set or modified, so that ¡¡NOTEPAD.EXE is run when files with extensions of TXT are opened/launched:

HKCR\txtfile\shell\open\command
(default)
¡¡NOTEPAD.EXE "%1"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer