Sophos

W32/Dref-AO

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 12 August 2007 15:22:34 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Dref-AO is a worm for the Windows platform.

When first run W32/Dref-AO copies itself to <Windows>\spooldr.exe and creates the file <System>\spooldr.sys.

W32/Dref-AO also infects the file tcpip.sys with a code that loads the Trojan driver spooldr.sys into memory and activates it. Spooldr.sys contains code to hide the presence of the dropped malicious files.

The files spooldr.sys and tcpip.sys are detected as Troj/Dorf-M.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer