Sophos

Troj/HacDef-DR

Aliases
  • Backdoor.Win32.HacDef.hj
  • Win32/HacDef
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 29 December 2006 14:39:48 (GMT)
Last updated 10 January 2007 05:48:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/HacDef-DR is a backdoor Trojan for the Windows platform.

Troj/HacDef-DR contains functionality to hide information about the infected computer.

The Trojan reads configuration data from an INI file with the same basename as the Trojan filename. This file is also detected as Troj/HacDef-DR.

Troj/HacDef-DR may create the file <System>\hxdefdrv.sys which also detected as Troj/HacDef-DR.

The file hxdefdrv.sys is registered as a system driver service named "winntbaken
", with a display name of "ROME ROTYUS" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\winntbaken\

Troj/HacDef-DR may copy itself to the file <System>\r_server.exe. The following registry entry may be set to run the Trojan copy on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
r_server
<System>\r_server.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer