Sophos

Troj/SpamThru-B

Aliases
  • Backdoor.Win32.Agent.uu
  • Spam-DComServ
  • TROJ_AGENT.BOR
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 March 2006 14:26:39 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/SpamThru-B is a Trojan for the Windows platform.

Troj/SpamThru-B can be used to send unsolicited emails as specified by a remote user.

Troj/SpamThru-B creates the following registry entries:

HKCR\CLSID\(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)\InProcServer32
<default>
<Path to Trojan DLL>

HKCR\CLSID\(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)\InProcServer32
ThreadingModel
Apartment

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ SharedTaskScheduler
(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)
DCOM Server

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
DCOM Server
(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer