Sophos

Troj/Hackvan-A

Aliases
  • BackDoor-CTV
  • TROJ_VANTI.B
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2005 (3.98)
Protection available since 3 September 2005 15:06:37 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Hackvan-A is a Trojan for the Windows platform.

Troj/Hackvan-A can be used in conjunction with other malware to hide or delete running processes and prevent them from being detected.

The Trojan can drop a file named God.sys in the Windows system folder. This file is registered as a new system driver service named "VANTI", with a display name of "VANTI" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\VANTI\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer