Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 6 May 2005 20:31:30 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdranck-D is a multi-component network worm.
W32/Sdranck-D drops two files to the winnt\system32 folder, EDETOYASY.EXE and XICAC.EXE. EDETOYASY.EXE is the Troj/Ranck-CQ proxy Trojan and XICAC.EXE is the W32/Sdbot-YC network worm. It is this latter file that spreads W32/Sdranck-D to network shares with weak passwords and via network security exploits.
