HackerDefender100 -ugh!

Configure and optimize you computer for Audio.
Post Reply New Topic
RELATED
PRODUCTS

Post

I consider myself one to stay on top of window's updates, but maybe this one got pass me. HackerDefender is a NT Rootkey backdoor. I honestly don't know how I got it, but it will mask itself deeply in your system. I guess it can be used for a number of purposes, including the routing of traffic thru ports it opens but makes hidden from your system. The backdoor will hide it's reg entries, as well as it's actual files. It leaves very few traces of itself, and has the ability to bypass detection from virus scanners and what not. The only reason I noticed something was my machine was slightly sluggish, and the network icon in the taskbar was constantly lit. There was tons of traffic going thru my machine.

In any case, I'm writting this because the only solutions on the internet I found required using your windows install cd to go into recover console mode... and follow the procedures from there.

That seemed like a PITA, so I am posting an alternative solution which worked great on my system...

The driver for the stupid backdoor is called "hxdefdrv.sys", and it sits in your "c:\windows" directory. There will most likely be an entry labeled "c:\windows\svhost.exe -sr -l0" in your run and run once key in the registry. You will noticed that you won't be able to find svhost.exe because it's been hidden by the bastard.

My solution was to look for the actual backdoor on the net. I downloaded it. It's a file called "hxdef100.zip", which actually HAS a command line uninstall which removes memory resident aspects of the backdoor. I had to go to the command prompt and enter "hxdef100 svhost.exe -:uninstall". This will make it such that you can actually delete "hxdefdrv.sys" without it magically reappearing after boot. Upon reboot, you should bring up the task manager and kill the "svhost.exe" process (not svchost.exe), and make sure to delete any entries that reappear in your run/run once reg keys. You will also notice a few more files in your "c:\windows" directory. The 3 biggies are svhost.exe (not svchost.exe), winunins.exe, winunins.ini. These are just some of the bastards that were cloaked. If you look in the "winunins.ini" file, you'll see the config for the backdoor.. listed in there are other files you should search for and delete if you find them, as well as the hackerdefender100 reg keys (which should be deleted as well). You'll also see the config for scanners and what not this backdoor is set to bypass.

Argh! don't people have anything better to do with their time? I hope this helps anyone in the same situation. It's taken up most of my morning dealing with this stupid crap... ARGH! :x
ModuLR / Radio

Post

Hey, thanx for the heads up....i think i've noticed that "svhost.exe" running in my task manager before too....gonna check it out. Thanx again!

Peace!

Post

I hate those damn hackers too...

One thing people can do to drastically reduce the chance of geting a virus/mask/trojan (besides using a firewall) is to change their browser to ANY alternative browser if they are using Internet Explorer.

IE is built on over 2 year old technology, and it is full of security holes in almost every aspect of the program (for example people can take control over your computer, people can install software/viruses etc without you knowing it if you are using IE as your main browser). Internet Explorer IS a backdoor into your computer when you are surfing.

Personally i use this browser http://www.opera.com/

Post

Thanks for the info modulr!

I agree Erki. I tell my clients the easiest, and most effective way to protect yourself from spyware and virii is to not use IE and especially Outlook Express. Both are filled with security holes, and more importantly are the #1 target for hackers.

I use the Firefox + Thunderbird combo personally.

Post Reply

Return to “Computer Setup and System Configuration”