Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2007 (4.18) |
| Protection available since | 21 April 2007 15:34:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bckdr-QHT is a Trojan for the Windows platform.
When first run Troj/Bckdr-QHT copies itself to <System>\taskmanager.exe and creates the following files:
<Windows>\hkr32.asm
<System>\ldapi32.exe
<System>\ntcvx32.dll
<System>\ntswrl32.dll
The file ldapi32.exe is detected as Troj/Bckdr-ITU and the file ntswrl32.dll is detected as Troj/Bckdr-IGQ.
The following registry entry is created to run taskmanager.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
taskmgr
<System>\taskmanager.exe
The following registry entry is set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<System>\taskmanager.exe
<System>\taskmanager.exe:*:Enabled:Dnode
Registry entries are created under:
HKCU\Software
