Troj/HacDef-R is a backdoor Trojan for the Windows platform that is targeted at NT/2000/XP operating systems. As well as allowing unauthorized remote access to the victim's computer, this Trojan is also able to hide information about the victim's system including files, folders, processes, services and registry entries.
Troj/HacDef-R is usually located in the Windows system folder with the filename scrss.exe.
In order to be able to run automatically when Windows starts up Troj/HacDef-R sets the registry entry:
HKLM\SYSTEM\CurrentControlSet\Services\scrss
ImagePath
<System>\scrss.exe
Once installed Troj/HacDef-R also creates a number of entries under the following registry entry:
HKLM\SOFTWARE\Network Associates\TVD