Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Feb 19, 2009 | Updated Sep 15, 2017

Spammer:WinNT/Srizbi.A

Detected by Microsoft Defender Antivirus

Aliases: Troj/RKAgen-Fam (Sophos) Rootkit.Win32.Agent.bab (Kaspersky) Trojan.Srizbi (Symantec)

Summary

Spammer:WinNT/Srizbi.A is a detection for the kernel mode component of the WinNT/Srizbi family. It patches varied native APIs and the NTFS file system driver to avoid detection. It can also hide its network traffic from the system firewall and monitoring programs to avoid detection of its spamming activity.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us