Sophos

Troj/Haxdoor-DL

Aliases
  • Backdoor.Win32.Haxdoor.jw
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 8 January 2007 05:58:20 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Haxdoor-DL is a Trojan for the Windows platform.

When Troj/Haxdoor-DL is installed the following files are created:

<System>\eetvpn.dll
<System>\eetvpn.sys
<System>\eexvpn.sys
<System>\kgctini.dat
<System>\lps.dat
<System>\qo.dll
<System>\qo.sys

The files eetvpn.dll, eetvpn.sys, eexvpn.sys, qo.dll and qo.sys are detected as Troj/Haxdor-Fam.

The following registry entries are created to run code exported by eetvpn.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\eetvpn
DllName
eetvpn.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\eetvpn
Startup
ER03Sb5fex

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\eetvpn
Impersonate
1

The file eexvpn.sys is registered as a new system driver service named "eexvpn", with a display name of "MCRT accelerator". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\eexvpn

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer