Sophos

Troj/Haxdoor-DI

Aliases
  • Trojan-Spy.Win32.Haxspy.ax
  • Win32/Spy.Goldun.HP
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2006 (4.12)
Protection available since 19 October 2006 12:15:10 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Haxdoor-DI is a backdoor Trojan for the Windows platform.

Troj/Haxdoor-DI includes functionality to:

- stealth its files, processes and registry entries
- inject its code into other processes

Sophos's anti-virus products include Behavioral Genotype™ Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against Troj/Haxdoor-DI (detected as Mal/Packer) since version 4.10. Troj/Haxdoor-DI is a backdoor Trojan for the Windows platform.

Troj/Haxdoor-DI includes functionality to:

- stealth its files, processes and registry entries
- inject its code into other processes

When Troj/Haxdoor-DI is installed the following files are created:

<System>\arprmdg0.dll
<System>\arprmdg5.sys
<System>\ksl48.bin

The following registry entries are created to run code exported by arprmdg0.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
DllName
arprmdg0.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
Startup
arprmdg0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arprmdg0
Impersonate
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer