Sophos

Troj/HacDef-GZ

Aliases
  • Backdoor.Win32.HacDef.gz
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2006 (4.12)
Protection available since 29 October 2006 16:20:54 (GMT)
Detected by All Sophos products

Action

More Information

Troj/HacDef-GZ is a rootkit for the Windows platform.

Troj/HacDef-GZ contains functionality to hide the presence of processes, files and services. Troj/HacDef-GZ is a rootkit for the Windows platform.

Troj/HacDef-GZ contains functionality to hide the presence of processes, files and services.

Troj/HacDef-GZ is registered as a new system driver service named "guowaaayu", with a display name of "Print Spooler Service" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\guowaaayu\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer