Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 19 October 2006 12:15:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-DI is a backdoor Trojan for the Windows platform.
Troj/Haxdoor-DI includes functionality to:
- stealth its files, processes and registry entries
- inject its code into other processes
Sophos's anti-virus products include Behavioral Genotype™ Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against Troj/Haxdoor-DI (detected as Mal/Packer) since version 4.10. Troj/Haxdoor-DI is a backdoor Trojan for the Windows platform.
Troj/Haxdoor-DI includes functionality to:
- stealth its files, processes and registry entries
- inject its code into other processes
When Troj/Haxdoor-DI is installed the following files are created:
<System>\arprmdg0.dll
<System>\arprmdg5.sys
<System>\ksl48.bin
The following registry entries are created to run code exported by arprmdg0.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
DllName
arprmdg0.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
Startup
arprmdg0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
Impersonate
1
