Home Malware Programs Backdoors Sparta.d

Sparta.d

Posted: March 28, 2006

Sparta.d is a backdoor controlled through IRC channels. It gives the attacker unauthorized remote access to a compromised PC. The intruder can manage running processes, download and execute arbitrary files, collect computer information, scan hosts in a local network and reconfigure the backdoor. Sparta.d can also be used to record all user keystrokes and run a hidden FTP server. The threat hides its running components by injecting malicious code into legitimate computer processes such as winlogon.exe. Sparta.d runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ntmem32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonsystem
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}F5776D81-BB64-2883-8E84-B0B283D8BCEF
Loading...