Threat Database Trojans Trojan.Spamship

Trojan.Spamship

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 10,193
Threat Level: 90 % (High)
Infected Computers: 1,688
First Seen: September 27, 2011
Last Seen: September 6, 2023
OS(es) Affected: Windows

Trojan.Spamship is a Trojan that is created to take advantage of the security flaw in Windows operating system. Once infected, Trojan.Spamship will spread spam email messages through the malicious devices. Trojan.Spamship can access specified location on the web and connect to specified SMTP server to send phishing spam. The spam email involves a malicious attachment that was detected as Trojan.Swifi that will try to exploit certain Adobe Flash Player and Adobe Acrobat vulnerability to further damage the compromised PC. Trojan.Spamship will change system settings and creates its start-up registry entry to run automatically every time you turn your computer on. Uninstall Trojan.Spamship before it harms your machine.

File System Details

Trojan.Spamship may create the following file(s):
# File Name Detections
1. %CurrentFolder%\[ORIGINAL THREAT FILE NAME].exe

Registry Details

Trojan.Spamship may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"Type" = "272"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"FailureActions" = "[BINARY DATA]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"ConfigFlags" = "0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Service" = "AdobeTM4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"DisplayName" = "AdobeTM4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ErrorControl" = "0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"Start" = "2"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Legacy" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Class" = "LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ImagePath" = "%CurrentFolder%\[ORIGINAL THREAT FILE NAME].exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\Security\"Security" = "[BINARY DATA]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ObjectName" = "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"DeviceDesc" = "AdobeTM4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\"NextInstance" = "1"

Trending

Most Viewed

Loading...