Sophos

Troj/SpamToo-AY

Aliases
  • TR/Rootkit.Gen
  • Trojan-Proxy.Win32.Small.du
  • Trojan-Proxy.Win32.Small.ck
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 25 February 2008 10:27:12 (GMT)
Detected by All Sophos products

Action

Due to its stealthing functionality, removal of Troj/SpamToo-AY will require the use of Sophos Anti-Rootkit. When scanned using this tool, a computer infected with Troj/SpamToo-AY will report an "Unknown hidden process" and a "Hidden registry value" both referring to a hidden file. Additionally, many legitimate Windows system files will also be reported as hidden that should not be removed. Therefore, select clean-up for only the file referred to as a hidden process.

More Information

Troj/SpamToo-AY is a Trojan for the Windows platform.

Troj/SpamToo-AY uses stealthing functionality in order to hide its operations; refer to "additional recovery instructions" for removal information.

Troj/SpamToo-AY communicates with a remote server via HTTP to utilise infected computers as spam relays.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer