Sophos

Troj/Bdoor-HO

Aliases
  • BackDoor-CQZ
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 April 2005 07:03:13 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bdoor-HO is a backdoor Trojan for the Windows platform.

When first run, Troj/Bdoor-HO will attempt to copy itself to C:\recycler\system.exe. The Trojan will set the following registry entries in an attempt to run itself on Windows login:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Recycle Bin Handler 2005
C:\recycler\system.exe

Troj/Bdoor-HO will attempt to connect to an IRC channel and await commands from a remote user. Infected computers can then be used to perform several tasks including:

record keystrokes
gather filesystem information
update itself
download arbitrary files
execute arbitrary files

The Trojan will also attempt to modify Windows XP Firewall settings to allow itself access to a specified port.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer