Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 13 September 2006 12:56:38 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-DD is a backdoor Trojan for the Windows platform.
When Troj/Haxdoor-DD is installed the following files are created:
<System>\ksl48.bin
<System>\scsipsrvc.sys
<System>\scsiusr4.dll
scsipsrvc.sys and scsiusr4.dll are both detected as Troj/Haxdoor-DD. ksl48.bin is an empty file.
Troj/Haxdoor-DD includes functionality to:
- stealth its files, processes and registry entries
- inject its code into other processes
Troj/Haxdoor-DD modifies the HOSTS file, changing the URL-to-IP mappings for selected websites, therefore preventing normal access to these sites.
The following registry entries are created to run code exported by scsiusr4.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\scsiusr4
DllName
scsiusr4.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\scsiusr4
Startup
scsiusr4
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\scsiusr4
Impersonate
1
