Sophos

W32/Trode-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 13 October 2005 22:20:58 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Trode-A is a worm for the Windows platform.

W32/Trode-A spreads to drives E: to Z:.

W32/Trode-A attempts to start the Telnet service and stop the Themes service.

W32/Trode-A copies itself to the following locations:

C:\Windows\Today's Results.vbs
C:\Windows\System32\Backup.A\Backup.Bak
C:\Program Files\AntiBot\Setup.exe
C:\Program files\AntiBot\Setup.exe
C:\Documents and settings\all users\start menu\programs\startup\Today's Results.vbs
E:\Today's Results.vbs
F:\Today's Results.vbs
G:\Today's Results.vbs
H:\Today's Results.vbs
I:\Today's Results.vbs
J:\Today's Results.vbs
K:\Today's Results.vbs
L:\Today's Results.vbs
M:\Today's Results.vbs
N:\Today's Results.vbs
O:\Today's Results.vbs
P:\Today's Results.vbs
Q:\Today's Results.vbs
R:\Today's Results.vbs
S:\Today's Results.vbs
T:\Today's Results.vbs
U:\COOL\Today's Results.vbs
V:\Today's Results.vbs
W:\Today's Results.vbs
X:\Today's Results.vbs
Y:\Today's Results.vbs
Z:\Today's Results.vbs

W32/Trode-A sets the following registry entries in order to run automatically on computer login:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Pex Sound Driver
C:\Windows\Today's Results.vbs

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
pex Sound driver 2
U:\Today's Results.vbs

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer