Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2007 (4.17) |
| Protection available since | 11 March 2007 05:37:49 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bdoor-ACX is a Trojan for the Windows platform.
When run, Troj/Bdoor-ACX copies itself as
the following registry entry to hook system startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GenericHostXP
<Windows>\WinLoaderXP.exe
Once running, Troj/Bdoor-ACX sends notification via email to its author,
reporting the IP of the victim. Troj/Bdoor-ACX contains code to connect to a
remote server and download code, in order to self-update.
Troj/Bdoor-ACX logs to the following file:
<Windows>\troya.log (may be safely deleted)
