Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jun 09, 2005 | Updated Sep 15, 2017

VirTool:WinNT/Syspro.A

Detected by Microsoft Defender Antivirus

Aliases: Win-Trojan/Commonnme.124649 (AhnLab) Adware Generic.SJ (AVG) Trojan.Commonnme.A (BitDefender) Trojan.Win32.CommonName.a (Kaspersky) Adware-CommonName (McAfee) CommonName.J.dropper (Norman) Spyware/CommonName (Panda) Troj/Rootkit-AZ (Sophos) CommonName (Sunbelt Software) Adware.CommonName (Symantec)

Summary

VirTool:WinNT/Syspro.A is a component of BrowserModifier:Win32/CommonName, unwanted software that mainly tracks Internet usage for marketing purposes, while providing advertising and search assistance with typed keywords. VirTool:WinNT/Syspro.A is installed via a Nullsoft installation program (NSIS archive).
 
VirTool:WinNT/Syspro.A is a kernel mode rootkit that may exist as a file WINIK.SYS and hide processes, files and registry keys. WinNT/Syspro.A intercepts registry system calls and attaches to file system driver to filter the file IO requests.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us