Threat Database Backdoors Backdoor.POISON.BQA

Backdoor.POISON.BQA

By ZulaZuza in Backdoors

Backdoor.POISON.BQA is a dangerous trojan infection that comes as attachment to email messages spammed by another malware parasite or malicious user in an effort to control your PC. Backdoor.POISON.BQA is being illustrated on falsified security alerts called 'Resident Shield: New virus detected' created by rogue anti-spyware Antivirus 7. It is highly recommended to delete Antivirus 7 before it causes more harm to your computer system.

File System Details

Backdoor.POISON.BQA may create the following file(s):
# File Name Detections
1. %Program Files\AV7\antivirus7.exe
2. %WINDOWS\system32\UpdateExplorer.dll
3. %Program Files\AV7
4. WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
5. %Documents and Settings\All Users\Start Menu\AV7
6. %UserProfile%\Desktop\Antivirus7.lnk
7. %Documents and Settings\All Users\Start Menu\AV7\Antivirus7.lnk
8. %Documents and Settings\All Users\Start Menu\AV7\Uninstall.lnk

Registry Details

Backdoor.POISON.BQA may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\EVA246
HKEY_CLASSES_ROOT\CLSID\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}

Trending

Most Viewed

Loading...