Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 12 July 2005 20:42:33 (GMT) |
| Last updated | 27 March 2006 04:43:04 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Vaq-A is a Trojan downloader for the Windows platform.
When first run Troj/Vaq-A copies itself to:
<Windows system folder>\rundIl32.exe
<Windows system folder>\¡¡NOTEPAD.EXE
The following registry entry is created to run rundIl32.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe rundIl32.exe
The following registry entry is set or modified, so that ¡¡NOTEPAD.EXE is run when files with extensions of TXT are opened/launched:
HKCR\txtfile\shell\open\command
(default)
¡¡NOTEPAD.EXE "%1"
