Home Malware Programs Trojans QQify

QQify

Posted: March 28, 2006

QQify is a trojan, which carries a quite dangerous payload and performs many annoying actions on the compromised PC. The spyware can secretly download from the Internet and run arbitrary files, create multiple copies of certain files, change the screen resolution and the computer time. It can also control the CD-ROM drive, restart or turn off a PC. QQify automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c.exe
    2 comline.ini
    3 msconfig.exe
    4 nsconfig.exe
    5 regedit.exe
    6 regedita.exe
    7 win2000.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERControlPanelInternationaliHfhy=1HKEY_CURRENT_USERSoftwareBeyondSoftHfhyHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSystemKey
Loading...