Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 13 December 2005 22:28:43 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Hackvan-B is a Trojan for the Windows platform.
Troj/Hackvan-B can be used in conjunction with other malware to hide or delete running processes and prevent them from being detected.
The Trojan can drop 2 files with random filenames and SYS extentions to the temporary folder. These file are registered as new system driver services named "DER005" and "XRW005", with the same display name and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\DER005\
HKLM\SYSTEM\CurrentControlSet\Services\XRW005\
