Sophos

Troj/Xorpix-Z

Aliases
  • Trojan-Proxy.Win32.Xorpix.m
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 29 June 2007 20:53:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Xorpix-Z is a proxy Trojan for the Windows platform.

Troj/Xorpix-Z allows network traffic to be routed through an infected computer as specified by a remote intruder.

Troj/Xorpix-Z is typically installed to <System>\a3dx8.dll and the following registry entries are created to run code exported by a3dx8.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\A3dxq
DllName
<System>\a3dx8.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\A3dxq
Impersonate
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\A3dxq
Startup
Startup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer