Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2007 (4.14) |
| Protection available since | 29 December 2006 14:39:48 (GMT) |
| Last updated | 10 January 2007 05:48:56 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/HacDef-DR is a backdoor Trojan for the Windows platform.
Troj/HacDef-DR contains functionality to hide information about the infected computer.
The Trojan reads configuration data from an INI file with the same basename as the Trojan filename. This file is also detected as Troj/HacDef-DR.
Troj/HacDef-DR may create the file <System>\hxdefdrv.sys which also detected as Troj/HacDef-DR.
The file hxdefdrv.sys is registered as a system driver service named "winntbaken
", with a display name of "ROME ROTYUS" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\winntbaken\
Troj/HacDef-DR may copy itself to the file <System>\r_server.exe. The following registry entry may be set to run the Trojan copy on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
r_server
<System>\r_server.exe
