Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 22 November 2005 22:16:00 (GMT) |
| Last updated | 2 December 2005 14:04:23 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/HacDef-AB is a backdoor Trojan that is targeted at NT/2000/XP operating systems.
As well as allowing unauthorized remote access to the victim's computer, Troj/HacDef-AB is able to hide information about the victim's system including files, folders, processes, services and registry entries.
An installation of Troj/HacDef-AB may include the following files:
wdl.exe
wdl.dll
xxxdefdrv.sys
windows.exe
xmlsvc.exe
xmldata.dll
xmlsvc.dll
.tmp
rpcsvc.exe
ioservice.exe
ioservice.ini
rpcsvr.exe
smap.exe
sv.exe
diketraffic.conf
dikeentry.conf
bitsm.exe
kern32.dll
bitsm.exe -start
iobanana.exe
ioA.exe
where wdl.exe is an main installer component and wdl.dll is a related configuration script of the Trojan, xxxdefdrv.sys is a system driver component that runs as a service with the name "Microsoft Information Driver".
