Sophos

Troj/PPdoor-P

Aliases
  • Backdoor.Win32.PPdoor.bl
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 19 October 2005 20:55:15 (GMT)
Last updated 28 October 2005 12:55:07 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PPdoor-P is a Trojan for the Windows platform.

When Troj/PPdoor-P is installed the following data files are created:

<System>\swbkbtaa.dll (may be safely deleted)
<System>\vnetbsh.dll (may be safely deleted)

The following registry entry is created to run code exported by the Trojan library on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad
Internet Agent
(413A8AAE-74E4-4ED7-9190-D6367CBB6F44)

Troj/PPdoor-P copies itself to the Windows system folder as photes.exe and sets the following registry entry in order to run each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Client Agent
"<Windows system folder>\photes.exe"

The Trojan connects to several remote sites and may download and install additional files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer