Sophos

W32/Sdranck-B

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 25 February 2005 21:40:46 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdranck-B is a multi-component network worm.

W32/Sdranck-B drops components detected by Sophos's anti-virus products as W32/Sdbot-Fam and Troj/Ranck-CC.

The dropped Sdbot component spreads W32/Sdranck-B to network shares with weak passwords and via network security exploits. W32/Sdranck-B is a multi-component network worm.

W32/Sdranck-B drops two files in the following locations:

C:\WINNT\SYSTEM32\ipazysud.exe
C:\WINNT\SYSTEM32\pinaduli.exe

W32/Sdranck-B then runs these files.

IPAZYSUD.EXE is a proxy Trojan detected as Troj/Ranck-CC. PINADULI.EXE is a member of the W32/Sdbot family of network worms.

The latter file attempts to spread W32/Sdranck-B to network shares with weak passwords and via network security exploits.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer