Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 28 August 2005 15:13:37 (GMT) |
| Last updated | 6 September 2005 13:27:07 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-AI is a backdoor Trojan incorporating stealth functionality which allows a remote intruder to gain access and control over the computer. Troj/Haxdoor-AI is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Haxdoor-AI includes functionality to:
- stealth its files, processes, registry entries and services
- prevent itself being terminated
- prevent itself being deleted
- disable other software, including anti-virus, firewall and security related applications
When Troj/Haxdoor-AI is installed the following files are created:
<System>\msftcpip.sys
<System>\tcpGDC.dll
The following registry entries are created to run code exported by tcpGDC.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpGDC
DllName
tcpGDC.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpGDC
Startup
tcpGDC
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tcpGDC
Impersonate
1
The file msftcpip.sys is registered as a new system driver service named "msftcpip", with a display name of "TCPservice". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\msftcpip\
Troj/Haxdoor-AI may modify the HOSTS file, mapping the URLs of selected anti-virus and security related websites to a loopback IP address, in an attempt to prevent access to these sites.
