Backdoor:Win32/Haxdoor.DK takes the following actions:
- Drops the following files to the Windows system folder:
avpx32.sys
avpx64.sys
avpx32.dll
klogini.dll
- Injects avpx32.dll into the following processes:
explorer.exe
iexplore.exe
opera.exe
myie.exe
mozilla.exe
thebat.exe
outlook.exe
msn.exe
icq.exe
- Adds C:\WINDOWS\Explorer.EXE to the Windows Firewall authorized application list
- Disables the Windows Firewall
- Disables Outpost firewall software
- Monitors keystrokes
- Collects user passwords and account information from the machine
- Posts collected data to a remote Web site
- Creates a backdoor on port 16661 which allows remote control of machine
- Communicates between infected processes via named pipes
- Hides files and processes
To load when Windows is started, Backdoor:Win32/Haxdoor.DK installs itself as a Winlogon Notification Package, modifying the registry as follows:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avpx32
Value: "Impersonate"
Type: REG_DWORD
Data: 01, 00, 00, 00
Value: "MaxWait"
Type: REG_DWORD
Data: 01, 00, 00, 00
Value: "secureTIME"
Type: REG_SZ
Data: 2:8
Value: "secureUID"
Type: REG_SZ
Data: [8251264222536966936]
Value: "Startup"
Type: REG_SZ
Data: MmMapView3
Adds the following registry keys to enable its drivers for safe mode:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\avpx32.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\avpx64.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\avpx32.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\avpx64.sys
Turns off kernel memory page write protection by modifying the registry as follows:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management "EnforceWriteProtection"
Type: REG_DWORD
Data: 00, 00, 00, 00
Makes additional registry modifications as follows:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avpx32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avpx64
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avpx32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avpx64