Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 6 November 2005 02:52:26 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/OptixP-N is a backdoor Trojan for the Windows platform.
The Trojan runs continuously in the background allowing a remote attacker to access and control the infected computer.
Troj/OptixP-N copies itself to the Windows system folder as securewinload32x.exe and system32dir2a.exe. It adds the following registry entries to ensure that a copy is run each time a user logs on :
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random characters>
<System>\securewinload32x.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
<random characters>
<System>\securewinload32x.exe
