Sophos

Troj/Haxdoor-CN

Aliases
  • Backdoor.Win32.Haxdoor.cn
  • BackDoor-BAC.gen.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2005 (3.93)
Protection available since 31 March 2005 13:15:17 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Haxdoor-CN is a backdoor Trojan that provides unauthorised access to an infected system.

Troj/Haxdoor-CN drops the following components in the Windows system folder:

cz.dll
drct16.dll
hz.sys
vdmt16.sys
winlow.sys
wz.sys

These components are all detected as Troj/Haxdoor-CN.

Troj/Haxdoor-CN attempts to use stealthing to prevent the detection and removal of its files, registry entries and services, as well as providing the means to restore them if they are removed.

Troj/Haxdoor-CN may register WINLOW.SYS as a service "winlow" with display name "SCNDmem". The Trojan may register VDMT16.SYS as a driver "vdmt16" with display name "VIRTwin".

Troj/Haxdoor-CN may create the following registry entries in order to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drct16
DllName
drct16.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drct16
Startup
MeMessager

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer