Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 30 May 2005 06:21:16 (GMT) |
| Last updated | 21 June 2005 18:59:57 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Network Services Controller
<System>\mmsvc32.exe
and delete it if it exists.
Close the registry editor.
More Information
W32/Nanpy-A is a worm for the Windows platform. It may spread to vulnerable computers via the RPC-DCOM exploit, and attempt to redirect access to various banking websites. W32/Nanpy-A is a worm for the Windows platform. It may spread to vulnerable computers via the RPC-DCOM exploit, and attempt to redirect access to various banking websites.
When first run W32/Nanpy-A copies itself to <System>\mmsvc32.exe.
The following registry entry is created to run mmsvc32.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Network Services Controller
<System>\mmsvc32.exe
W32/Nanpy-A modifies the HOSTS file, mapping the URLs of banking websites to a remote IP. At the time of writing, this IP address is not functional.
lloydstsb.co.uk
online.lloydstsb.co.uk
www.lloydstsb.co.uk
www.lloydstsb.com
personal.barclays.co.uk
barclays.co.uk
ibank.barclays.co.uk
www.barclays.co.uk
www.nwolb.com
nwolb.com
hsbc.co.uk
www.hsbc.co.uk
abbey.com
www.abbey.com
www.abbey.co.uk
abbey.co.uk
cahoot.com
www.cahoot.com
www.cahoot.co.uk
cahoot.co.uk
www.co-operativebank.co.uk
co-operativebank.co.uk
www.co-operativebank.com
co-operativebank.com
welcome2.co-operativebankonline.co.uk
welcome6.co-operativebankonline.co.uk
welcome8.co-operativebankonline.co.uk
welcome10.co-operativebankonline.co.uk
www.smile.co.uk
smile.co.uk
