Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2006 (4.06) |
| Protection available since | 24 April 2006 12:47:18 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bckdr-HLO is a backdoor Trojan for the Windows platform.
The Trojan includes functionality to connect to the predefined remote site awaitng for the further remote commands. Troj/Bckdr-HLO is a backdoor Trojan for the Windows platform.
When Troj/Bckdr-HLO is installed the following files are created:
<Temp>\winword.exe
<System>\awext32.dll
<System>\w32time.exe
The file w32time.exe is registered as a service named "W32Time" (repacing any existing services named "W32Time"). Registry entries are created or modified under:
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\
The file awext32.dll is injected into the msmsgs.exe process space and includes functionality to connect to the predefined remote site awaitng for the further remote commands.
