Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2005 (3.93) |
| Protection available since | 31 March 2005 13:15:17 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-CN is a backdoor Trojan that provides unauthorised access to an infected system.
Troj/Haxdoor-CN drops the following components in the Windows system folder:
cz.dll
drct16.dll
hz.sys
vdmt16.sys
winlow.sys
wz.sys
These components are all detected as Troj/Haxdoor-CN.
Troj/Haxdoor-CN attempts to use stealthing to prevent the detection and removal of its files, registry entries and services, as well as providing the means to restore them if they are removed.
Troj/Haxdoor-CN may register WINLOW.SYS as a service "winlow" with display name "SCNDmem". The Trojan may register VDMT16.SYS as a driver "vdmt16" with display name "VIRTwin".
Troj/Haxdoor-CN may create the following registry entries in order to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drct16
DllName
drct16.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drct16
Startup
MeMessager
