Home Malware Programs Backdoors Backdoor.POISON.BQA

Backdoor.POISON.BQA

Posted: February 15, 2011

Backdoor.POISON.BQA is a malicious trojan virus that comes as attachment to email messages spammed by another malware infection or malicious user in a try to control your PC. Backdoor.POISON.BQA is the most hazardous and most widespread type of spyware program that opens a backdoor in your PC and enables the hacker to issue commands remotely to control the compromised PC. Backdoor.POISON.BQA will download files to the computer without your consent which will put system security in danger. Backdoor.POISON.BQA can even enable an attacker to have remote access to the compromised computer Backdoor.POISON.BQA is being demonstrated on false security alerts called 'Resident Shield: New virus detected' created by rogue anti-spyware Antivirus 7. It is highly recommended to delete Backdoor.POISON.BQA it makes more damages to your PC system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings\All Users\Start Menu\AV7
    2 %Documents and Settings\All Users\Start Menu\AV7\Antivirus7.lnk
    3 %Documents and Settings\All Users\Start Menu\AV7\Uninstall.lnk
    4 %Program Files\AV7
    5 %Program Files\AV7\antivirus7.exe
    6 %UserProfile%\Desktop\Antivirus7.lnk
    7 %WINDOWS\system32\UpdateExplorer.dll
    8 WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVA246HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}
Loading...