Backdoor.Cazno is a Trojan horse that allows an attacker to control a compromised system.
Copies itself as %System%\CAZNOVAS.exe.
Listens on a configurable port, waiting for the commands from an attacker.
Uses ICQ or IRC to send the attacker information on a compromised system.
The ICQ contact and IRC server are configurable.
Allows the attacker to control the computer and do any of the following:
- Obtain system information
- List/start/stop processes
- Control window functions (show/hide windows)
- Log keystrokes, steal passwords
- Shut down and restart the computer
- Control the Web camera
- Control file system (list, delete, rename, and create files)
Automatic removal:
Use RegRun Startup Optimizer to remove it from startup.
For manual removal, please delete any value that looks like:
"CAZNOVAS" = %system%\CAZNOVAS.exe"
in the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Removal: CAZNOVAS.exe is removed by RegRun.
Read more... Removal instructions...
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
June 30 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?