Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2006 (4.05) |
| Protection available since | 27 March 2006 21:09:55 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Hearse-A is a Trojan for the Windows platform.
The Trojan creates two files detected as members of the Haxdoor family of password stealing Trojans. Troj/Hearse-A is a Trojan for the Windows platform.
When run the Trojan creates the following files:
<Windows system folder>\zopenssl.dll
<Windows system folder>\zopenssld.sys
The file zopenssl.dll is detected as Troj/Haxdor-Fam and the file zopenssld.sys is detected as Troj/Haxdor-Gen.
The following registry entries are created in order to load the zopenssl.dll file each time a user logs on:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Asynchronous
dword:00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
DllName
zopenssl.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Impersonate
dword:00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
MaxWait
dword:00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
nk48id
"[88BF38A86A50D1EAA]"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Startup
"zopenssl"
