Sophos

Troj/Bckdr-PNO

Aliases
  • IM-Worm.Win32.Sohanad.o
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2006 (4.12)
Protection available since 6 November 2006 05:23:59 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bckdr-PNO is an Instant Messaging Trojan for the Windows platform.

When first run Troj/Bckdr-PNO copies itself to:

<User>\Application Data\App\<random filename1>.exe
<System>\<random filename2>.exe
<System>\<random filename3>.exe
<Windows>\regedit.exe

The following registry entry is created to run Troj/Bckdr-PNO on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winValidate
<System>\<random filename2>.exe delnext <System>\<random filename3>.exe

The following registry entry is set, disabling the registry editor (regedit):

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Conf\

Troj/Bckdr-PNO may periodically send the following IM messages with links to non-malicious websites:

'<url>
So funny =)) '

'<url>
Hav never seen such funny pics =)) '

'<url>
write back to me if you feel the same'

'Wow =))
<url>'

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer