Sophos

Troj/Hackvan-B

Aliases
  • Rootkit.Win32.Vanti.aa
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 13 December 2005 22:28:43 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Hackvan-B is a Trojan for the Windows platform.

Troj/Hackvan-B can be used in conjunction with other malware to hide or delete running processes and prevent them from being detected.

The Trojan can drop 2 files with random filenames and SYS extentions to the temporary folder. These file are registered as new system driver services named "DER005" and "XRW005", with the same display name and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\DER005\

HKLM\SYSTEM\CurrentControlSet\Services\XRW005\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer