Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 2 May 2007 09:24:12 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/SpamToo-AL is a Trojan for the Windows platform.
When run Troj/SpamToo-AL copies itself to <System>\comippwa.exe.
The following registry entry is set to run Troj/SpamToo-AL on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
p2snetis
<System>\comippwa.exe
The following registry entries are also set:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\DomainProfile\AuthorizedApplications\List\
<System>\comippwa.exe
<System>\comippwa.exe:*:Enabled:Server
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List\
<System>\comippwa.exe
<System>\comippwa.exe:*:Enabled:Server
Troj/SpamToo-AL has the abilty to send HTML messages with any of the following contents:
"You are not authorized to view this page <username>"
"Your account has been suspended, <username>"
"Your account has expired (<username>)"
"Your are welcome!You send errors."
