PDA

View Full Version : Got Hackdef!!


Master
08-28-06, 18:54
Hi

the Microsoft Windows Malicious Software Removal Tool found on my server the HackDef trojan, it is remove or i need to do other control?

---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.19, August 2006
Started On Wed Aug 23 03:00:53 2006

Quick Scan Results:
----------------
Found virus: Backdoor:Win32/Hackdef.Z in file C:\WINNT\system32\trkupd.exe
Found virus: VirTool:WinNT/Hackdef.E in file C:\WINNT\system32\trkupd.sys

Quick Scan Removal Results
----------------
Deleting service TrkUpd
Operation succeeded !

Deleting service TrkUpdDrv
Operation succeeded !

Deleting file C:\WINNT\system32\trkupd.exe
Operation succeeded !

Deleting file C:\WINNT\system32\trkupd.sys
Operation succeeded !

Deleting file C:\WINNT\system32\trkupd.exe
Operation had previously completed.

Deleting file C:\WINNT\system32\trkupd.sys
Operation had previously completed.

For cleaning Backdoor:Win32/Hackdef.Z, the system needs to be restarted.
For cleaning VirTool:WinNT/Hackdef.E, the system needs to be restarted.

Results Summary:
----------------
For cleaning Backdoor:Win32/Hackdef.Z, the system needs to be restarted.
For cleaning VirTool:WinNT/Hackdef.E, the system needs to be restarted.

Return code: 10
Microsoft Windows Malicious Software Removal Tool Finished On Wed Aug 23 03:01:06 2006


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.19, August 2006
Started On Fri Aug 25 11:58:14 2006

Results Summary:
----------------
Found Backdoor:Win32/Hackdef.Z and Removed!
Found VirTool:WinNT/Hackdef.E and Removed!

Return code: 6
Microsoft Windows Malicious Software Removal Tool Finished On Fri Aug 25 11:59:26 2006

Rubal
08-28-06, 19:18
Are you running some unpatches / old version of MailEnable. If yes then upgrade it immediately and apply all hotfixes.

Also make sure none of your customers are running old vulnerable versions of IPB, PHPBB, Joomla etc ..

Thanks

zombie
08-28-06, 23:49
does the Microsoft Windows Malicious Software Removal Tool run during the boot process or once the machine comes up fully?

Rubal
08-29-06, 06:53
does the Microsoft Windows Malicious Software Removal Tool run during the boot process or once the machine comes up fully?

After machine comes up ..

snake
08-30-06, 01:42
if you have a backdoor trojan then your server may well have been compromised already. you should run a rootkit detector and fully check your system.

br
08-30-06, 02:54
even that may not be good enough, as some more advanced rootkits cant even be detected.

if you have data u must keep secure, i would format and reinstall a fresh copy of windows.