Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | June 2007 (4.18) |
| Protection available since | 9 November 2006 11:31:51 (GMT) |
| Last updated | 14 April 2007 01:16:18 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Nordex-A is a downloading Trojan for the Windows platform.
Troj/Nordex-A includes functionality to access the internet and communicate with a remote server via HTTP. Troj/Nordex-A is a downloading Trojan for the Windows platform.
Troj/Nordex-A includes functionality to access the internet and communicate with a remote server via HTTP.
The Trojan may arrive disguising itself as a genuine MS update in an archive dropper that contains a Trojan downloading component.
When Troj/Nordex-A is installed the following files are created:
<User>\Local Settings\Temp\<random>.tmp.exe
<User>\Local Settings\Temp\<random>.tmp.dll
<User>\Local Settings\Temp\WER1.tmp.dir00/appcompat.txt
<Windows>\kb823980.log
<System>\xpsp1hfm.exe
<Windows>\xpsp1hfm.log
where the <random>.tmp.dll file is also detected as Troj/Nordex-A. The rest of the files are not malicious and may be safely deleted.
Registry entries are set under :
HKCU\Software\Microsoft\Notepad
