Backdoor.Cazno is a Trojan horse that allows an attacker to control a compromised system.
Copies itself as %System%\CAZNOVAS.exe.
Listens on a configurable port, waiting for the commands from an attacker.
Uses ICQ or IRC to send the attacker information on a compromised system.
The ICQ contact and IRC server are configurable.
Allows the attacker to control the computer and do any of the following:
- Obtain system information
- List/start/stop processes
- Control window functions (show/hide windows)
- Log keystrokes, steal passwords
- Shut down and restart the computer
- Control the Web camera
- Control file system (list, delete, rename, and create files)
Automatic removal:
Use RegRun Startup Optimizer to remove it from startup.
For manual removal, please delete any value that looks like:
"CAZNOVAS" = %system%\CAZNOVAS.exe"
in the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Removal: CAZNOVAS.exe is removed by RegRun.
Read more... Removal instructions...
UnHackMe - Rootkit/Malware killer
Recommended:
RegRun Security Suite Platinum Detects and removes rootkits/malware/adware that your antivirus could not.
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
March 6 2010
We recommend! Click Here to Update All your PC's Outdated drivers
Would you like to add your opinion?