|
|
Trojan.sp2chk Trojan Information
| Name: |
Trojan.sp2chk |
| Category: |
Trojan |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
This trojan is a rootkit written for NT-based Windows Operating Systems. The rootkit is used to hide files and processes on the affected computer.
When executed the trojan silently copies itself with the same filename as the original executable to the %System% directory, and then deletes the original executable.
It also drops a .DLL component (which may be detected as Win32/Aluroot.A.DLL.Trojan by CA antivirus solutions). The file name of the .DLL file may vary, however, it always starts with the letters "HD" appended by a few random characters. For example: HDKJ.DLL, HDAH.DLL. The size of the .DLL is static at 12,169 bytes.
The trojan also hides its process, and any files or registry entries it has created from view. An affected user will not be able to veiw these trojan system modifications using the regular utilities, such as Regedit, or Windows Explorer.
|
| Signatures:
|
process: sp2chk.exe: MD5 Hash: 53d817e3efca6a7a9ba.. |
| Type: |
Trojan - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Trojan Visited Pages:
Tro.Downloader.loadadv - 408 visits
Enable Regedit - 191 visits
Java.ClassLoader.Dummy.d - 182 visits
Trojan.BankerSpy - 176 visits
RBot.steam - 85 visits
Startup.NameShifter.Xgtray - 76 visits
Tro.Bagle.SP - 58 visits
Trojan.BHO.NameShifter.EZ - 54 visits
LRPatch Trojan - 54 visits
Tro.YourStartingPage - 53 visits
Random Trojan Pages:
Armoury Trojan - Alias: Timebomb.dr, Trojan.Armoury
Backdoor.DSSdoor
SRV.Netdsg-Keylogger
Trojan.Startup.NameShifter.AN
Bingo.1963.Batch
Trojan.winfirewall - Alias: winfirewall, winfire, Win32 Firewall Drivers
LRPatch Trojan
Trojan.Startup.NameShifter.M
Trojan.BHO.NameShifter.GC
Win95.Tuil
|
|