Troj/NtRootK-AX is a backdoor Trojan with rootkit functionality. When run Troj/NtRootK-AX creates a service with a name identical to the base filename of the Trojan file.
Troj/NtRootK-AX installs two drivers, xHide.sys and GxNdisHook.sys. The purpose of the drivers is to hide the presence of malicious files, registry entries and TCP ports used by malware.
Troj/NtRootK-AX provides the attacker with an interface for the remote control over the machine.