Skip to main content
Published Jan 08, 2007 | Updated Sep 15, 2017

Backdoor:Win32/Haxdoor.CG

Detected by Microsoft Defender Antivirus

Aliases: BackDoor-BAC.dll (McAfee) Backdoor.Haxdoor.D (Symantec) Troj/Haxdoor-CN (Sophos) BKDR_HAXDOOR.BN (Trend Micro)

Summary

Backdoor:Win32/Haxdoor.CG is an NT-based driver component of Backdoor:Win32/Haxdoor.CN, a rootkit-enabled trojan that gathers private user data and sends it to remote attackers. Data collected by Backdoor:Win32/Haxdoor.CN might include user names and passwords, credit card numbers, bank logon credentials, or other sensitive financial information. On NT-based systems, files and processes related to a Backdoor:Win32/Haxdoor.CN infection may be hidden by a kernel-mode rootkit component. (This component is also detected as Backdoor:Win32/Haxdoor.CG). The Backdoor:Win32/Haxdoor.CN trojan also disables firewall software and may perform other malicious actions, such as clearing CMOS settings, destroying disk data, or shutting down Windows unexpectedly.
Backdoor:Win32/Haxdoor.CN includes a backdoor component that could allow remote attackers to upload and install other malicious software on affected systems. The trojan also includes a rootkit component that masks the presences of files, processes, and other system changes made by the trojan. As a result, attempting manual removal of Win32/Hackdoor.CN is not recommended. To detect and remove Win32/Hackdoor.CN, run a full-system scan with an up-to-date antivirus product such as the Microsoft Malicious Software Removal Tool (http://www.microsoft.com/security/malwareremove/default.mspx) or the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us