Sophos

Troj/HacDef-BR

Aliases
  • Backdoor.Win32.HacDef.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from April 2006 (4.04)
Protection available since 21 February 2006 04:59:48 (GMT)
Detected by All Sophos products

Action

More Information

Troj/HacDef-BR is a backdoor Trojan for the Windows platform.

When run Troj/HacDef-BR attempts to drop a rootkit driver and run it, installing it as a service with the name "ThOrxDriver". The driver is detected by Sophos as Troj/HacDef-G.

Registry changes are made to:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
HKLM\SYSTEM\CurrentControlSet\Services\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer