Sophos

Troj/Haxdoor-AG

Aliases
  • Trojan-Spy.Win32.Goldun.bf
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2005 (3.97)
Protection available since 14 July 2005 22:02:05 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Haxdoor-AG is a backdoor Trojan for the Windows platform.

Troj/Haxdoor-AG allows a remote attacker to run arbitrary commands. The Trojan may download and run further malicious code.

The Trojan uses stealthing techniques to avoid being terminated.

When Troj/Haxdoor-AG is installed the following files are created:

<System>\msudp4.sys
<System>\tcpG4T.dll

The file msudp4.sys provides stealthing functionality and has detected as Troj/Haxdor-Gen since version 3.93.

The following registry entries are created to run code exported by tcpG4T.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
DllName
tcpG4T.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
Startup
tcpG4T

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpG4T
Impersonate
1

The file msudp4.sys is registered as a new system driver service named "msudp4", with a display name of "UDPservice". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\msudp4\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer