Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 25 February 2008 10:27:12 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Due to its stealthing functionality, removal of Troj/SpamToo-AY will require the use of Sophos Anti-Rootkit. When scanned using this tool, a computer infected with Troj/SpamToo-AY will report an "Unknown hidden process" and a "Hidden registry value" both referring to a hidden file. Additionally, many legitimate Windows system files will also be reported as hidden that should not be removed. Therefore, select clean-up for only the file referred to as a hidden process.
More Information
Troj/SpamToo-AY is a Trojan for the Windows platform.
Troj/SpamToo-AY uses stealthing functionality in order to hide its operations; refer to "additional recovery instructions" for removal information.
Troj/SpamToo-AY communicates with a remote server via HTTP to utilise infected computers as spam relays.
