Sophos

Troj/SpamToo-AL

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 May 2007 09:24:12 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/SpamToo-AL is a Trojan for the Windows platform.

When run Troj/SpamToo-AL copies itself to <System>\comippwa.exe.

The following registry entry is set to run Troj/SpamToo-AL on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
p2snetis
<System>\comippwa.exe

The following registry entries are also set:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\DomainProfile\AuthorizedApplications\List\
<System>\comippwa.exe
<System>\comippwa.exe:*:Enabled:Server

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List\
<System>\comippwa.exe
<System>\comippwa.exe:*:Enabled:Server

Troj/SpamToo-AL has the abilty to send HTML messages with any of the following contents:

"You are not authorized to view this page <username>"
"Your account has been suspended, <username>"
"Your account has expired (<username>)"
"Your are welcome!You send errors."

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer