Sparta.d
Sparta.d is a backdoor controlled through IRC channels. It gives the attacker unauthorized remote access to a compromised PC. The intruder can manage running processes, download and execute arbitrary files, collect computer information, scan hosts in a local network and reconfigure the backdoor. Sparta.d can also be used to record all user keystrokes and run a hidden FTP server. The threat hides its running components by injecting malicious code into legitimate computer processes such as winlogon.exe. Sparta.d runs on every Windows startup.
File System Modifications
- The following files were created in the system:
# File Name 1 ntmem32.dll
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonsystem - The following CLSID's were detected:
HKEY..\..\{CLSID Path}F5776D81-BB64-2883-8E84-B0B283D8BCEF
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.