Home Malware Programs Trojans Trojan.Spamnost

Trojan.Spamnost

Posted: December 23, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 9
First Seen: December 23, 2011
Last Seen: March 22, 2022
OS(es) Affected: Windows

Trojan.Spamnost is a dangerous Trojan that is used by hackers to send spam emails. When Trojan.Spamnost is executed, it makes changes to the affected computer system. Trojan.Spamnost modifies the registry so that it can run every time Windows starts. Trojan.Spamnost also creates the certain registry entries to bypass the Windows Firewall policy for unrestricted Internet access and to change Internet Explorer settings. Trojan.Spamnost then accesses certain URLs in a try to gain new configuration parameters to use for sending spam emails. Uninstall Trojan.Spamnost before it damages your machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\ntuser.dat File name: %UserProfile%\Application Data\ntuser.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\desktop.ini File name: %UserProfile%\Application Data\desktop.ini
Mime Type: unknown/ini
Group: Malware file
%UserProfile%\Application Data\[RANDOM CHARACTERS]\svcnost.exe File name: %UserProfile%\Application Data\[RANDOM CHARACTERS]\svcnost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"mssend" = "\"%UserProfile%\Application Data\[RANDOM CHARACTERS]\svcnost.exe\""HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\[RANDOM CHARACTERS]\svcnost.exe" = "%UserProfile%\Application Data\[RANDOM CHARACTERS]\
Loading...