Sophos

Troj/Haxdoor-BX

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from June 2006 (4.06)
Protection available since 3 May 2006 05:22:09 (GMT)
Last updated 9 May 2006 09:11:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Haxdoor-BX installs a backdoor Trojan for the Windows platform.

Troj/Haxdoor-BX creates the files flashdrvr.dll and flashdrv3.sys in the Windows system folder.

Flashdrvr.dll is detected as Troj/Haxdor-Fam.
Flashdrv3.sys is detected as Troj/Haxdor-Gen.

The Trojan creates registry entries in the following location to ensure that flashdrvr.dll is started each time Windows starts:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\flashdrvr\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer