Sophos

Troj/Dluca-M

Aliases
  • TrojanDownloader.Win32.Dluca.ai
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 27 September 2004 08:38:54 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

When first run Troj/Dluca-M copies itself to the Windows system folder as sp2ctr.exe and creates the following registry entry, so that sp2ctr.exe is run automatically on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
sp2ctr = %SYSTEM%\sp2ctr.exe /nocomm

Registry entries are also created under:

HKCU\Software\sp2ctr\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sp2ctr\

Troj/Dluca-M can be uninstalled via the Add or Remove Programs dialog in the Windows Control Panel (Start -> Settings -> Control Panel -> Add/Remove Programs by selecting "sp2ctr" from the list.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer