Proactive IT security
 Home  News  Products & services  Virus & security  Support  Download  Partner  Purchase
Select country
Select product
W32/Haxdoor Destructivity: Medium Spreading: None Overall risk: Low
Detected by virus detection files published: 2003
Virus characteristics first published: 31 Jan. 2007
Virus characteristics latest update: 13 Feb. 2007
Type: Backdoor, Kit, Trojan
Spreading mechanism: Email, Webpage
Overall risk: Low
Payload: Backdoor, keylogger, rootkit, interferes with security software
Type Spreading mechanism Destructivity & payload Additional descriptions Detection & removal

Haxdoor is a large family of backdoor and rootkit combinations. This was first found as early as 2003, but is still being distributed at the time of writing.

The malware is created by a creation kit that is for sale on the Internet, and that allows attackers to easily make custom variants. Several hundred variants (at least) exist.

Typical Installation

The trojan is installed via malicious web pages or spammed out as attachments to email.  Once run, it usually copies several components to the %SYSTEM% folder and registers one of them as a service. It then modifies registry keys so that specified functions will be called in this service.

Example:

File system changes:

Creates file %TEMP%10320054.gif.
Creates file %SYSTEM%\dvb03a.dll.
Creates file %SYSTEM%\qo.dll.
Creates file %SYSTEM%\dvb06a.sys.
Creates file %SYSTEM%\qo.sys.
Creates file%SYSTEM%\dvb03a.sys.
Deletes file lps.dat.

Registry changes:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dvb03a".
DllName=dvb03a.dll
Startup=DVBz637890

HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dvb06a.sys  ""=Driver
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\dvb06a.sys". ""=Driver
HKLM\System\CurrentControlSet\Services\dvb06a
ImagePath=%SYSTEM%\dvb06a.sys
DisplayName=WDVB 05

In this example the malware uses the name dvb06a, but names used are variable. Usually installations will include at least one driver (*.SYS) and one library (*.DLL) and be installed by an executable (*.EXE).

Once installed, the malware components will typically neither be visible in the process list nor as files on disk, and special tools or rootkit-aware antimalware utilities are needed to uncover their presence.

The variables %SITE% and %SYSTEM% refers to specific web sites used, and the Windows System folder, respectively.

 

 

 

 

 

 

CURRENT VIRUS THREATS
Medium risk
15 Aug 08 AntiVirus 2008
24 Oct 07 Pidief.A
24 Jan 07 Tibs
25 Sep 06 Stration
18 Jan 06 Small.KI
12 Sep 05 Bagle.CS
17 Aug 05 Zotob.B
08 Jun 05 Mytob
17 Feb 05 MyDoom.AQ
26 Jul 04 MyDoom.L
25 Mar 04 Netsky.P
Low risk
05 Mar 07 Viking.GT
27 Jan 06 Feebs
16 Jan 05 MyDoom.AH
22 Apr 04 SDBot
30 Mar 04 Netsky.Q
Latest virus definition file published
2008-09-05
Norman is one of the world’s leading companies within the field of data security. With products for antivirus (virus control), personal firewall, antispam, and encryption, the company plays an important role in the data industry.