Sophos

Troj/SpamToo-AX

Aliases
  • Email-Worm.Win32.Mydoom.bj
  • Win32/SpamTool.Agent.NAJ
  • Generic.dx
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from January 2008 (4.25)
Protection available since 28 November 2007 03:09:06 (GMT)
Detected by All Sophos products

Action

More Information

Troj/SpamToo-AX is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

When Troj/SpamToo-AX is installed it creates the file <System>\drivers\protect.sys.

The file protect.sys is detected as Troj/NTRootK-CG.

The file protect.sys is registered as a new system driver service named "protect", with a display name of "protect". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\protect

Sophos's anti-virus products include Behavioral Genotype® Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against Troj/SpamToo-AX (detected as Mal/Behav-104) since version 4.17.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer