Sophos

Troj/SpamThru-A

Aliases
  • Trojan.Win32.Agent.pk
  • Spam-DComServ
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from April 2006 (4.04)
Protection available since 24 February 2006 14:43:58 (GMT)
Detected by All Sophos products

Action

More Information

Troj/SpamThru-A is a Trojan for the Windows platform.

Troj/SpamThru-A can be used to send unsolicited emails as specified by a remote user.

Troj/SpamThru-A creates the following registry entries:

HKCR\CLSID\(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)\InProcServer32
<default>
<Path to Trojan DLL>

HKCR\CLSID\(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)\InProcServer32
ThreadingModel
Apartment

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)
DCOM Server

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
DCOM Server
(2C1CD3D7-86AC-4068-93BC-A02304BB8C34)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer