Skip to main content
Published Oct 03, 2006 | Updated Sep 15, 2017

Backdoor:Win32/Haxdoor.CN

Detected by Microsoft Defender Antivirus

Aliases: BackDoor-BAC.dll (McAfee) Backdoor.Haxdoor.D (Symantec) Troj/Haxdoor-AF (Sophos) BKDR_HAXDOOR.BN (Trend Micro)

Summary

Backdoor:Win32/Haxdoor.CN is a rootkit-enabled backdoor trojan that gathers private user data and sends it to remote attackers. Collected data might include user names and passwords, credit card numbers, bank logon credentials, or other sensitive financial information. On NT-based systems, files and processes related to a Backdoor:Win32/Haxdoor.CN infection may be hidden by a kernel-mode rootkit component. The Backdoor:Win32/Haxdoor.CN trojan also disables firewall software and may perform other malicious actions, such as clearing CMOS settings, destroying disk data, or shutting down Windows unexpectedly. Certain components of the trojan may be detected by Microsoft as Backdoor:Win32/Haxdoor.CG.
Backdoor:Win32/Haxdoor.CN includes a backdoor component that could allow remote attackers to upload and install other malicious software on affected systems. The trojan also includes a rootkit component that masks the presences of files, processes, and other system changes made by the trojan. As a result, attempting manual removal of Win32/Hackdoor.CN is not recommended. To detect and remove Win32/Hackdoor.CN, run a full-system scan with an up-to-date antivirus product such as the Microsoft Malicious Software Removal Tool (http://www.microsoft.com/security/malwareremove/default.mspx) or the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us