Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 23 May 2006 21:17:32 (GMT) |
| Last updated | 25 June 2006 19:51:45 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Spammit-D is a backdoor Trojan which allows an infected computer to send emails as instructed by a remote attacker.
The following registry entry is created to run Troj/Spammit-D on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WINDOWS
<pathname of the Trojan executable>
The following registry entries are set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
DomainProfile\AuthorizedApplications\List
<pathname of the Trojan executable>
<pathname of the Trojan executable>:*:Enabled:Server
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
StandardProfile\AuthorizedApplications\List
<pathname of the Trojan executable>
<pathname of the Trojan executable>:*:Enabled:Server
