Sophos

Troj/PPdoor-E

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Web downloads
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 23 April 2005 17:09:51 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

Change any data that may have become compromised.

More Information

Troj/PPdoor-E is a backdoor Trojan for the Windows platform. When the Trojan is run it copies itself into the Windows system folder as comsutil.exe.

Troj/PPdoor-E allows unauthorised access to remote intruders. The Trojan may attempt to disable security-related software including the Windows XP Firewall. The Trojan allows remote attackers to redirect internet traffic through the infected computer using a SOCKS server, download new code and updates and steal system information.

The Trojan may create files in the Windows system folder called "ngaasaaa.dll" and "msnet64.dll".

Troj/PPdoor-E also creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Meeting Connection
<System>\comsutil.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
Shedule Address
<random CLSID>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer