Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 6 November 2006 05:23:59 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bckdr-PNO is an Instant Messaging Trojan for the Windows platform.
When first run Troj/Bckdr-PNO copies itself to:
<User>\Application Data\App\<random filename1>.exe
<System>\<random filename2>.exe
<System>\<random filename3>.exe
<Windows>\regedit.exe
The following registry entry is created to run Troj/Bckdr-PNO on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winValidate
<System>\<random filename2>.exe delnext <System>\<random filename3>.exe
The following registry entry is set, disabling the registry editor (regedit):
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Conf\
Troj/Bckdr-PNO may periodically send the following IM messages with links to non-malicious websites:
'<url>
So funny =)) '
'<url>
Hav never seen such funny pics =)) '
'<url>
write back to me if you feel the same'
'Wow =))
<url>'
