March 22, 2010

8/15: CMQ.a Virus for Parasitically Infected Files

W32/CMQ.a is a virus for parasitically infected files that loads and executes BackDoor-CMQ.

Infected Win32 Portable Executable (PE) files have their import address table patched to load a DLL component detected as BackDoor-CMQ with one of the following filename(s):

mrpmsg.dll
rsapmsg.dll

When successful, the BackDoor-CMQ component executes in the memory space of the infected file.

More information can be found at this McAfee page.

1
IT Offers

Partners