Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2006 (4.04) |
| Protection available since | 16 February 2006 20:56:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Theef-N is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
When first run Troj/Theef-N copies itself to <Windows>\halmon.exe and creates the following files:
\[RandomName].bat
<Windows>\winhnd64.drv
The files [RandomName].bat and winhnd64.drv are clean and can be deleted.
The following registry entry is created to run halmon.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Hardware Mon
<Windows>\halmon.exe
