Sophos

Troj/PPdoor-C

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2005 (3.93)
Protection available since 12 March 2005 18:04:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PPdoor-C is a backdoor Trojan for the Windows platform.

Troj/PPdoor-C allows unauthorised access to remote intruders. The Trojan may attempt to disable security-related software including the Windows XP Firewall. The Trojan allows remote attackers to redirect internet traffic through the infected computer using a SOCKS server, download new code and updates and steal system information.

Troj/PPdoor-C will not install itself after June 2005.

The Trojan may create files in the Windows system folder called "atitray.dll" and "msnet64.dll" as well as DLL files with names composed of random letters.

Troj/PPdoor-C creates the following registry entry in order to run automatically on computer login:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad\
NTDBGTOOL =
<random CLSID>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer