Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | September 2005 (3.97) |
| Protection available since | 14 July 2005 22:02:05 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-AG is a backdoor Trojan for the Windows platform.
Troj/Haxdoor-AG allows a remote attacker to run arbitrary commands. The Trojan may download and run further malicious code.
The Trojan uses stealthing techniques to avoid being terminated.
When Troj/Haxdoor-AG is installed the following files are created:
<System>\msudp4.sys
<System>\tcpG4T.dll
The file msudp4.sys provides stealthing functionality and has detected as Troj/Haxdor-Gen since version 3.93.
The following registry entries are created to run code exported by tcpG4T.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
DllName
tcpG4T.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
Startup
tcpG4T
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
Impersonate
1
The file msudp4.sys is registered as a new system driver service named "msudp4", with a display name of "UDPservice". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\msudp4\
