Alert ID : FrSIRT/ALRT-2008-02748
Aliases : BackDoor-CEP.svr - BKDR_BIFROSE.AQR
Size : N/A
Rated as : Low Risk Release Date : 2008-05-09
Description
Troj/Bckdr-QNJ is a Trojan for the Windows platform. When first run Troj/Bckdr-QNJ copies itself to <System>\ctfmon\ctfmon.exe and creates the following files: <User>\Application Data\addon.dat <Temp>\27b31.dmp <System>\ctfmon\klog.dat The following registry entry is created to run Troj/Bckdr-QNJ on startup: HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836} stubpath <System>\ctfmon\ctfmon.exe s Registry entries are created under: HKCU\Software\ctfmon.