Followup Information about this Trojan:
After installing it on my test machine, it has made the following modifications:
in C:\WINDOWS\WIN.INI, it added the string:
run=bkqvjturlon.exe
It also added the BKQVJTURLON.EXE file to my C:\WINDOWS directory.
It ALSO added the *.EXE file to my Registry, under the HKey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\RUN section. *sigh*
And again to the registry under HKey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\RunServices.
*still looking...*
in my C:\WINDOWS\SYSTEM.INI, it's added the line:
shell=Explorer.exe bkqvjturlon.exe
Back to the Registry again.. This time under:
HKey_Classes_ROOT\exefile\shell\open\command
it added the string:
\nmeusxj.exe %1 %*
ALL of this will need to be cleaned.. and the information from McAfee.Com will only be a starting point.
Again, the McAfee page that will show you how to get rid of most of this infection is located at:
http://vil.mcafee.com/dispVirus.asp?virus_k=10171&
Southern
Proprietor,
South's Maps & Market
Great Lakes
Eye yam aye tru beeleever inn hour edukashun sistum