Posted: August 29, 2011

Application.QueryMon is a malicious backdoor Trojan that uses rootkit techniques to open a back door for remote attackers to get access to an infected computer system. Application.QueryMon can install its malicious files and damage your PC system. Application.QueryMon opens a back door on a random TCP port, which enables the attacker to control your computer activity, access system configurations, steal personal information and delete system files. Application.QueryMon is a serious security threat that needs to be eliminated immediately.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:

%AppData%\Mcxaxm.exe File name: %AppData%\Mcxaxm.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\1.tmp File name: %AppData%\1.tmp
File type: Temporary File
Mime Type: unknown/tmp
%AppData%\2.exe File name: %AppData%\2.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Mcxaxm = "%AppData%\Mcxaxm.exe"