Home Malware Programs Trojans Trojan.Spamship

Trojan.Spamship

Posted: September 27, 2011

Threat Metric

Ranking: 19,160
Threat Level: 9/10
Infected PCs: 3,986
First Seen: September 27, 2011
Last Seen: March 5, 2025
OS(es) Affected: Windows

Trojan.Spamship is a Trojan infection that was generated specifically to send spam email messages. Trojan.Spamship can access specified location on the Internet and connect to specified SMTP server to send phishing spam. Trojan.Spamship conceals itself as an email from Chase Paymentech Team. When executed, Trojan.Spamship will modify the system registry and add itself as a system service to run itself automatically each time when you start Windows. The spam email includes a malicious attachment that was found as Trojan.Swifi that will try to exploit certain Adobe Flash Player and Adobe Acrobat vulnerability to further corrupt the targeted computer. Delete Trojan.Spamship as early as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CurrentFolder%\[ORIGINAL THREAT FILE NAME].exe File name: %CurrentFolder%\[ORIGINAL THREAT FILE NAME].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ImagePath" = "%CurrentFolder%\[ORIGINAL THREAT FILE NAME].exe"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"DisplayName" = "AdobeTM4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"Type" = "272"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\Security\"Security" = "[BINARY DATA]"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ErrorControl" = "0"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"FailureActions" = "[BINARY DATA]"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"ObjectName" = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeTM4\"Start" = "2"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"ConfigFlags" = "0"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"DeviceDesc" = "AdobeTM4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Legacy" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Service" = "AdobeTM4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\"NextInstance" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADOBETM4\0000\"Class" = "LegacyDriver"
Loading...