Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 18 April 2006 12:41:44 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/PPdoor-AS is a backdoor Trojan for the Windows platform.
When Troj/PPdoor-AS is installed the following files are created:
<Temp>\tmp1.bat
<System>\donvpihm.dll
<System>\sfcnmdd.exe
<System>\sigtfg32.dll
<System>\wiasdctr.dll
<System>\xobdhyzo.dll
The following registry entries are created to run sfcnmdd.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Update
<System>\sfcnmdd.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Update
<System>\sfcnmdd.exe
The following registry entry is changed to run sfcnmdd.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\sfcnmdd.exe
(the default value for this registry entry is "<Windows>\System32\userinit.exe,").
The following registry entry is created to run code exported by the worm library on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Protocol Connection
(EAC1DCE9-EB48-4782-95A5-27CCAE00B7AB)
The file sigtfg32.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\(EAC1DCE9-EB48-4782-95A5-27CCAE00B7AB)
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe,sfcnmdd.exe
