Home Malware Programs Trojans Hydraq

Hydraq

Posted: January 18, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 83
First Seen: January 19, 2011
OS(es) Affected: Windows

Hydraq is a Trojan that opens up a backdoor for malware to enter the system and has received media attention due to its connection with the cyber attack on Google. The hack attack targeted Gmail accounts of human rights activists who were involved in China rights issues. Hydraq may infect a users computer through a document attachment of a spam email message or an unpatched vulnerability in Microsoft's Internet Explorer. Once Hydraq has installed on a compromised computer, it uses a backdoor to listen for incoming commands, which allow Hydraq to generate malicious tasks.

Hydraq permits the attacker to carry out the following malicious tasks: modify the registry subkeys, delete files, execute and modify attributes, reboot or turn of the computer, alter token privileges, read and delete the %System%driversetcnetworks.ics file, and erase all system event logs. Hydraq also inspects if %System%acelpvc.dll is present so it can load it and call its EntryMain() export.

Hydraq attachs itself as the system service RaS[FOUR RANDOM CHARACTERS] and its "ImagePath" value is made to begin svchost.exe. To get svchost.exe to know the existence of Hydraq and be loaded, Hydraq adds its service name into the list of service names stored in the "netsvcs" value of the registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvcHost.

Hydraq can generate a copy of itself under a random filename in the %TEMP% directory or under the name %TEMP%c_1758.nls. We recommend that you obtain patches to fix Microsoft vulnerabilities and keep security software up-to-date.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Hydraq may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Related Posts

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.