Author Topic: Win32:Hacdef-G [Trj]  (Read 4332 times)

0 Members and 1 Guest are viewing this topic.

warhaug

  • Guest
Win32:Hacdef-G [Trj]
« on: October 28, 2005, 05:19:41 PM »
does anyone now how to remove this "Win32:Hacdef-G [Trj]"????
avast cannot delete it. if i put it in chest it just comes up again when i reboot. its located in "C:\msdos.exe" i think

NEED HELP!!!!!!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:Hacdef-G [Trj]
« Reply #1 on: October 28, 2005, 05:29:48 PM »
To clean a system from malware (and protect it against) follow the instructions in the malware removal section on this website: http://mrspock.dsmirc.co.uk

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:Hacdef-G [Trj]
« Reply #2 on: October 28, 2005, 06:30:38 PM »
Quote
Troj/HacDef-G is a backdoor Trojan that is targeted at NT/2000/XP operating systems. As well as allowing unauthorised remote access to the victim's computer, this Trojan is able to hide information about the victim's system including files, folders, processes, services and registry entries.

Alias: HackerDefender.

http://www.sophos.com/virusinfo/analyses/trojhacdefg.html

UnHackMe claims to be able to remove this rootkit, although new versions are constantly emerging:

http://www.greatis.com/unhackme/hackerdefenerremoval.htm

You could also try BlackLight from F-Secure:

http://www.f-secure.com/blacklight/

You can also find instructions for manual removal here.

http://bagpuss.swan.ac.uk/comms/hxdef.htm

Please let us know if UnHackMe works. I for one have never had the opportunity to test it.



     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: Win32:Hacdef-G [Trj]
« Reply #3 on: October 28, 2005, 11:45:40 PM »
Hi warhaug,

Ewido also removes this backdoor.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:Hacdef-G [Trj]
« Reply #4 on: October 29, 2005, 02:07:01 AM »
Ewido also removes this backdoor.
My beloved Ewido  :-* :-*
The best things in life are free.

Spiritsongs

  • Guest
Re: Win32:Hacdef-G [Trj]
« Reply #5 on: October 29, 2005, 02:33:42 AM »
 :) If none of the suggestions work, or the infection reappears,
     seek assistance on the forums of your antispyware
     provider(s) .