Another villain in the myriad of malicious code entities proliferating on the Internet has been discovered. This bug is called Backdoor.Sparta.C.
Backdoor.Sparta.C is a Trojan horse that creates a backdoor on infected systems that a remote cracker can use to gain entry into your system. The Trojan horse opens a port on all of your network interfaces and attempts to send an ICQ message to the cracker with information about your system, such as your IP address and the open port number.
In addition to this nasty little activity, it actively seeks out specific processes to terminate their execution and delete their source files. The files it seeks out are the core components of several widely used firewall and antivirus products.
Backdoor.Spart.C can infect systems running Windows 95, Windows 98, Windows Me, Windows NT, Windows 2000, Windows XP and the RC1 and beta releases of Windows .NET.
Fortunately, this malicious code entity was discovered early in its life in the wild. So far, it has infected few systems, is easily detected and is easy to remove from a system.
To detect and remove Backdoor.Sparta.C, perform the following:
- Update your antivirus product and perform a full system scan.
- Delete any files detected as infected with Backdoor.Sparta.C.
If your antivirus software was compromised by Backdoor.Sparta.C, then you must re-install your antivirus software before attempting the detection process.
Requires Free Membership to View
When you register, you’ll also receive targeted alerts from my team of editorial writers and independent industry experts with the latest news, tips, and advice to help you do your job more efficiently and effectively. Our goal is to keep you informed on the hottest topics and biggest challenges faced by IT professionals today working with desktop management and security technologies.
Cathleen A. Gagne, Senior Editorial DirectorOnce it has been detected and removed, re-install any firewall products to ensure they were not compromised.
Most antivirus products are able to detect, remove and disable this Trojan horse. For more information on this malicious code entity and various antivirus products that can be used to detect, protect and repair a system, see the following sites:
Symantec
McAfee
TrendMicro
About the author
James Michael Stewart is a researcher and writer for Lanwrights, Inc.
This was first published in October 2002