Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 12 August 2006 15:26:06 (GMT) |
| Last updated | 17 October 2006 02:43:20 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Haxdoor-CZ is a Trojan for the Windows platform.
When Troj/Haxdoor-CZ is installed the following files are created:
<System>\asusrx20.dll
<System>\asusrx25.sys
<System>\ksl48.bin
The file asusrx20.dll is also detected as Troj/Haxdoor-CZ, while the file asusrx25.sys is detected as Troj/Haxdor-Gen. The file ksl48.bin is a clean log file and may be deleted.
The following registry entries are created to run code exported by asusrx20.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\asusrx20
DllName
asusrx20.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\asusrx20
Startup
asusrx20
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\asusrx20
Impersonate
1
