Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 4 January 2006 21:09:19 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/HacDef-AM is a backdoor Trojan for the Windows platform.
As well as allowing remote attackers unauthorized access to the infected computer, the Trojan is able to hide its presence by hijacking operating system calls and preventing the user from viewing files, folders, processes, services, registry entries and/or network connections.
When run, Troj/HacDef-AM creates a file netsvcs.sys and registers the file as a system service. The following registry entries are created, yet are hidden by the Trojan:
HKLM\SYSTEM\CurrentControlSet\Services\NetSTrSvc
<Several entries>
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETSTRSVC
<Several entries>
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSTrSvc
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NetSTrSvc
